CVE-2016-10417: Race Condition
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, and SDX20, in QTEE, a TOCTOU vulnerability exists due to improper access control.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10417?
CVE-2016-10417 is a vulnerability in Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/1…
What is the severity of CVE-2016-10417?
The severity of CVE-2016-10417 is critical with a CVSS score of 8.1.
Which products are affected by CVE-2016-10417?
CVE-2016-10417 affects Google Android, Qualcomm Mdm9206 Firmware, Qualcomm Ipq4019 Firmware, Qualcomm Mdm9625 Firmware, Qualcomm Mdm9635m Firmware, Qualcomm Mdm9640 Firmware, Qualcomm Mdm9645 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Mdm9655 Firmware, and Qualcomm Sd series.
How can I fix CVE-2016-10417?
To fix CVE-2016-10417, update your Android device to a security patch level released after April 5, 2018.
Where can I find more information about CVE-2016-10417?
You can find more information about CVE-2016-10417 on the Security Focus website and the official Android Security Bulletin for April 2018.