CVE-2016-10437: Infoleak
In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear FSM9055, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20, while logging debug statements or ftrace events from rmnetdata, the socket buffer function uses normal format specifiers which may result in information exposure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10437?
CVE-2016-10437 is a vulnerability in Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC Snapdragon Mobile.
How severe is CVE-2016-10437?
The severity of CVE-2016-10437 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2016-10437?
Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear are affected.
How can I fix CVE-2016-10437?
Update Android to version after 2018-04-05 or apply the latest security patch from your device manufacturer.
Where can I find more information about CVE-2016-10437?
You can find more information about CVE-2016-10437 at the following references: [1](http://www.securityfocus.com/bid/103671), [2](https://source.android.com/security/bulletin/2018-04-01), [3](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).