CVE-2015-9160: Integer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, integer overflow may occur when values passed from HLOS (graphics driver busy time, and total time) in TZBSPGFXDCVSUPDATEID are very large.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9160?
The severity of CVE-2015-9160 is critical with a severity value of 9.8.
What is the affected software of CVE-2015-9160?
The affected software of CVE-2015-9160 includes Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800.
How do I fix CVE-2015-9160?
To fix CVE-2015-9160, it is recommended to apply the latest security patch level provided by Google for Android or Qualcomm for the affected devices.
Where can I find more information about CVE-2015-9160?
You can find more information about CVE-2015-9160 on the SecurityFocus website and the official Android Security Bulletin for April 2018.
What is the Common Weakness Enumeration (CWE) of CVE-2015-9160?
The Common Weakness Enumeration (CWE) of CVE-2015-9160 is CWE-190.