CVE-2016-10458: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, SDX20, and SnapdragonHighMed2016, the 'proper' solution for this will be to ensure that any users of qseelog in the bootchain (before Linux boots) unallocate their buffers and clear the qseelog pointer. Until support for that is implemented in TZ and the bootloader, enable tzlog to avoid potential scribbling. This solution will prevent the linux kernel memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10458?
CVE-2016-10458 is a vulnerability in Android devices that allows remote attackers to execute arbitrary code.
What is the severity of CVE-2016-10458?
The severity of CVE-2016-10458 is critical, with a CVSS score of 9.8.
Which devices are affected by CVE-2016-10458?
Android devices with Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, SDX20, and Snapdragon_High_ technology are affected by CVE-2016-10458.
How can I fix CVE-2016-10458?
To fix CVE-2016-10458, it is recommended to update your Android device to the latest security patch level available.
Where can I find more information about CVE-2016-10458?
You can find more information about CVE-2016-10458 on the official Android Security Bulletin and SecurityFocus websites.