CVE-2016-3843
Last modified
CVE-2016-3843 is a vulnerability of currently unknown severity. Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka Android internal bugs 28086229 and 29119870 and Qualcomm internal bug CR1011071.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka Android internal bugs 28086229 and 29119870 and Qualcomm internal bug CR1011071.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | <= 6.0.1 |
References
- http://source.android.com/security/bulletin/2016-08-01.htmlPatch, Vendor Advisory
- http://source.android.com/security/bulletin/2016-08-01.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-3843?
How severe is CVE-2016-3843?
How do I fix CVE-2016-3843?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-3837service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi …
- CVE-2016-3838Android 6.x before 2016-08-01 allows attackers to cause a de…
- CVE-2016-3839Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5…
- CVE-2016-3840Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5…
- CVE-2016-3841The IPv6 stack in the Linux kernel before 4.3.3 mishandles o…7.3
- CVE-2016-3842The Qualcomm GPU driver in Android before 2016-08-05 on Nexu…
- CVE-2016-3844mediaserver in Android before 2016-08-05 on Nexus 9 and Pixe…
- CVE-2016-3845The video driver in the kernel in Android before 2016-08-05 …
- CVE-2016-3846The Serial Peripheral Interface driver in Android before 201…
- CVE-2016-3847The NVIDIA media driver in Android before 2016-08-05 on Nexu…
- CVE-2016-3848The NVIDIA media driver in Android before 2016-08-05 on Nexu…
- CVE-2016-3849The ION driver in Android before 2016-08-05 on Pixel C devic…
Are you affected by CVE-2016-3843?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
