media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26323455.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: google_android
Published: 2016-04-18T00:00:00
Updated: 2024-08-05T23:24:49.286Z
Reserved: 2016-02-18T00:00:00
Link: CVE-2016-2419

No data.

Status : Deferred
Published: 2016-04-18T00:59:25.853
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-2419

No data.