---
title: "CVE-2016-2419\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-2419?format=md
keywords: index, follow
---

# CVE-2016-2419

Publication date 18 April 2016

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.8 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2016-2419?format=md#impact-score)

Toggle side navigation

## Description

media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01
does not initialize a certain key-request data structure, which allows
attackers to obtain sensitive information from process memory, and
consequently bypass an unspecified protection mechanism, via unspecified
vectors, as demonstrated by obtaining Signature or SignatureOrSystem
access, aka internal bug 26323455.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| android | 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored end of standard support |
| 15.10 wily | Ignored end of life |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

9.8 · Critical

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 9.8 · Critical |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2419)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-2419)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-2419)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-2419)

### Other references

* <https://android.googlesource.com/platform/frameworks/av/+/5a856f2092f7086aa0fea9ae06b9255befcdcd34>
* <http://source.android.com/security/bulletin/2016-04-02.html>
* <https://www.cve.org/CVERecord?id=CVE-2016-2419>
