CVE-2016-8459 describes a critical buffer overflow vulnerability within the Android storage subsystem, specifically affecting Linux Kernel version 3.18. This flaw arises from malformed parameters in listener responses to RPMB commands. With a CVSS score of 9.8 (Critical), it presents a severe risk, allowing unauthenticated attackers to achieve complete compromise of confidentiality, integrity, and availability over the network. While no public exploit code or active exploitation is currently reported, the vulnerability has garnered some community discussion and media attention, highlighting its potential impact despite its inactive status on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.