CVE-2016-8438: Linux Kernel
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.
Affected products
- Linux Linux Kernel: version 3.18 only
Published 2017-01-12. Last modified 2026-06-17.