PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6871 Facebook CVE debrief

CVE-2016-6871 is a critical issue in Facebook HHVM's bcmath component. The NVD description says an integer overflow in HHVM before 3.15.0 can trigger a buffer overflow, with unspecified impact and unknown vectors in the public summary. NVD rates the issue 9.8 with a network-exploitable vector and no privileges or user interaction required.

Vendor
Facebook
Product
Hhvm
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-17
Original CVE updated
2026-05-13
Advisory published
2017-02-17
Advisory updated
2026-05-13

Who should care

Teams operating or maintaining Facebook HHVM installations, especially those on affected versions, should prioritize this issue. Security teams responsible for PHP runtime platforms and downstream services that rely on HHVM should also review exposure.

Technical summary

The supplied NVD record identifies an integer overflow in HHVM's bcmath implementation that can lead to a buffer overflow. The description places affected versions before 3.15.0, and the CPE metadata marks versions through 3.14.5 inclusive. NVD maps the weakness to CWE-190 and lists a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Defensive priority

Immediate. The record rates the issue Critical with a 9.8 CVSS score and a vector indicating network access, low attack complexity, and no privileges or user interaction required.

Recommended defensive actions

  • Upgrade HHVM to version 3.15.0 or later, or to a vendor build that includes the fixed code.
  • Verify deployed HHVM versions against the affected range reported by NVD, which includes versions through 3.14.5 inclusive.
  • If immediate upgrading is not possible, reduce exposure by limiting network access to HHVM services and monitoring for crashes or abnormal behavior.
  • Confirm that downstream packages or containers include the Facebook HHVM patch referenced in the advisory materials.

Evidence notes

Primary evidence comes from the official NVD record and the CVE registry entry. NVD lists the weakness as CWE-190, affected HHVM versions through 3.14.5 inclusive, and a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Supporting references include two oss-security mailing list threads dated 2016-08-11 and 2016-08-19, plus the Facebook HHVM patch commit c00fc9d3003eb06226b58b6a48555f1456ee2475.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6871 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6871

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6871 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6871

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.