CVE-2016-5340 is a high-severity vulnerability affecting Google Android and Linux kernel versions 3.x, specifically within a Qualcomm Innovation Center (QuIC) Android patch. It stems from improper pointer validation in the is_ashmem_file function of the KGSL Linux Graphics Module, allowing attackers to bypass access restrictions by manipulating dentry names. With a CVSS score of 7.8, this local attack requires low privileges and no user interaction, potentially leading to high confidentiality, integrity, and availability impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in KEV, the vulnerability garnered significant media attention and community discussion, indicating its perceived importance at the time of discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | ||
>= 3.0, <= 3.19.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.