TOCTOU Vulnerability in Android Hypervisor PIL Authentication Bypass

TOCTOU Vulnerability in Android Hypervisor PIL Authentication Bypass

CVE-2016-8438 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.

Learn more about our Cis Benchmark Audit For Google Android.