CVE-2016-2066 describes an integer signedness error in the MSM QDSP6 audio driver within the Linux kernel 3.x, impacting Qualcomm-based Android devices. This vulnerability allows a crafted application to trigger memory corruption via an ioctl call, potentially leading to privilege escalation or denial of service. With a CVSS score of 7.8 (HIGH), it requires local access and user interaction (installing a malicious app) but can result in high confidentiality, integrity, and availability impacts. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it's not on the KEV catalog, it has received some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 3.19.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.