ubuntu · CVE-2016-0821

Quick triage

Priority: medium Published: 2016-03-12 00:00:00 UTC Updated: 2025-09-25 09:48:12 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-0821 medium priority: Ubuntu including 99 source packages (linux, linux-armadaxp, …), 828 status rows across 13 suites (artful, bionic, focal, jammy, noble, plucky, precise, trusty, upstream, wily, xenial, yakkety, zesty): DNE 549, not-affected 137, released 109, ignored 33.

Description:

The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug 26186802, a different vulnerability than CVE-2015-3636.

cvelogic Threat Intelligence