CVE-2016-2064 describes a buffer over-read vulnerability in the MSM QDSP6 audio driver (msm-audio-effects-q6-v2.c) within the Linux kernel 3.x, specifically impacting Qualcomm Innovation Center (QuIC) Android contributions for MSM devices. An attacker can trigger this flaw by crafting an application that makes an ioctl call with numerous commands, leading to a denial of service or potentially other unspecified impacts. With a CVSS score of 7.8 (HIGH), this vulnerability has a local attack vector, low attack complexity, and high potential for impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 3.19.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.