PatchSiren cyber security CVE debrief
CVE-2016-6871 Facebook CVE debrief
CVE-2016-6871 is a critical issue in Facebook HHVM's bcmath component. The NVD description says an integer overflow in HHVM before 3.15.0 can trigger a buffer overflow, with unspecified impact and unknown vectors in the public summary. NVD rates the issue 9.8 with a network-exploitable vector and no privileges or user interaction required.
- Vendor
- Product
- Hhvm
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-17
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-17
- Advisory updated
- 2026-05-13
Who should care
Teams operating or maintaining Facebook HHVM installations, especially those on affected versions, should prioritize this issue. Security teams responsible for PHP runtime platforms and downstream services that rely on HHVM should also review exposure.
Technical summary
The supplied NVD record identifies an integer overflow in HHVM's bcmath implementation that can lead to a buffer overflow. The description places affected versions before 3.15.0, and the CPE metadata marks versions through 3.14.5 inclusive. NVD maps the weakness to CWE-190 and lists a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
Immediate. The record rates the issue Critical with a 9.8 CVSS score and a vector indicating network access, low attack complexity, and no privileges or user interaction required.
Recommended defensive actions
- Upgrade HHVM to version 3.15.0 or later, or to a vendor build that includes the fixed code.
- Verify deployed HHVM versions against the affected range reported by NVD, which includes versions through 3.14.5 inclusive.
- If immediate upgrading is not possible, reduce exposure by limiting network access to HHVM services and monitoring for crashes or abnormal behavior.
- Confirm that downstream packages or containers include the Facebook HHVM patch referenced in the advisory materials.
Evidence notes
Primary evidence comes from the official NVD record and the CVE registry entry. NVD lists the weakness as CWE-190, affected HHVM versions through 3.14.5 inclusive, and a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Supporting references include two oss-security mailing list threads dated 2016-08-11 and 2016-08-19, plus the Facebook HHVM patch commit c00fc9d3003eb06226b58b6a48555f1456ee2475.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6871 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6871
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6871 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6871
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/facebook/hhvm/commit/c00fc9d3003eb06226b58b6a48555f1456ee2475
[email protected] - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.