CVE-2016-10412: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear FSM9055, MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, and SDX20, an integer overflow leading to buffer overflow can potentially occur in a memory API function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10412?
The severity of CVE-2016-10412 is critical with a severity value of 9.8.
Which software is affected by CVE-2016-10412?
Google Android, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9615 Firmware, Qualcomm Mdm9640 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Sd 210 Firmware, Qualcomm Sd 212 Firmware, Qualcomm Sd 205 Firmware, Qualcomm Sd 410 Firmware, Qualcomm Sd 425 Firmware, Qualcomm Sd 430 Firmware, Qualcomm Sd 450 Firmware, Qualcomm Sd 615 Firmware are affected by CVE-2016-10412.
How can I fix CVE-2016-10412?
To fix CVE-2016-10412, update your Android device to a security patch level later than April 5, 2018.
What is the Common Weakness Enumeration (CWE) ID of CVE-2016-10412?
The Common Weakness Enumeration (CWE) ID of CVE-2016-10412 is CWE-119, CWE-190.
Where can I find more information about CVE-2016-10412?
You can find more information about CVE-2016-10412 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/103671), [Android Security Bulletin](https://source.android.com/security/bulletin/2018-04-01), [Android Security Bulletin - Asterisk](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).