---
title: "CVE-2016-2427\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-2427?format=md
keywords: index, follow
---

# CVE-2016-2427

Publication date 18 April 2016

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2016-2427?format=md#impact-score)

Toggle side navigation

## Description

The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x,
recommends 12 octets for the aes-ICVlen parameter field, which might make
it easier for attackers to defeat a cryptographic protection mechanism and
discover an authentication key via a crafted application, aka internal bug
26234568. NOTE: The vendor disputes the existence of this potential issue
in Android, stating "This CVE was raised in error: it referred to the
authentication tag size in GCM, whose default according to ASN.1 encoding
(12 bytes) can lead to vulnerabilities. After careful consideration, it was
decided that the insecure default value of 12 bytes was a default only for
the encoding and not default anywhere else in Android, and hence no
vulnerability existed.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2016-2427?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| android | 17.10 artful | Not in release |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Ignored end of life |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| bouncycastle | 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2016-2427?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

no reverse depends in main
as of 2015-05-05, no equivalent fix in bouncycastle git repo,
this is an android issue, and is disputed

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| android | * Upstream:   <https://android.googlesource.com/platform/libcore/+/efd369d996fd38c50a50ea0de8f20507253cb6de> * Upstream:   <https://android.googlesource.com/platform/external/bouncycastle/+/b3bddea0f33c0459293c6419569ad151b4a7b44b> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2427)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-2427)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-2427)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-2427)

### Other references

* <http://source.android.com/security/bulletin/2016-04-02.html>
* <https://www.cve.org/CVERecord?id=CVE-2016-2427>
