Vulnerability record · CVE-2015-0569 · published 9 May 2016
CVE-2015-0569: Linux kernel out-of-bounds write vulnerability
Linux · Linux Kernel
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that establishes a packet filter.
Description
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that establishes a packet filter.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://source.android.com/security/bulletin/2016-05-01.html | Vendor Advisory |
| http://www.securityfocus.com/bid/77691 | Third Party AdvisoryVDB Entry |
| https://www.codeaurora.org/projects/security-advisories/multiple-issues-wlan-driver-allow-local-privilege-escalation-cve | Broken Link |
| https://www.exploit-db.com/exploits/39308/ | ExploitThird Party AdvisoryVDB Entry |
| http://source.android.com/security/bulletin/2016-05-01.html | Vendor Advisory |
| http://www.securityfocus.com/bid/77691 | Third Party AdvisoryVDB Entry |
| https://www.codeaurora.org/projects/security-advisories/multiple-issues-wlan-driver-allow-local-privilege-escalation-cve | Broken Link |
| https://www.exploit-db.com/exploits/39308/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2015-0569 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0569), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.