CVE-2016-10414: Critical severity Google Android vulnerability
In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, when a hash is passed with zero datalength, the code returns an error, even though zero data length is valid.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10414?
The severity of CVE-2016-10414 is critical with a severity value of 9.8.
Which Qualcomm products are affected by CVE-2016-10414?
Qualcomm Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, and more.
How can I fix CVE-2016-10414?
Apply the security patch level released on or after April 5, 2018 for Android devices.
What is the Common Weakness Enumeration (CWE) of CVE-2016-10414?
The Common Weakness Enumeration (CWE) of CVE-2016-10414 is CWE-388.
Where can I find more information about CVE-2016-10414?
You can find more information about CVE-2016-10414 at the following references: [1](http://www.securityfocus.com/bid/103671), [2](https://source.android.com/security/bulletin/2018-04-01), [3](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).