CVE-2016-10467: Critical severity android vulnerability
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, SD 820, and SD 820A, function cepkcs1psspaddingverifyautorecoversaltlen assumes that the size of the encoded message is equal to the size of the RSA modulus. This assumption is true for most RSA keys, but it fails when modulusbitlen % 8 == 1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10467?
CVE-2016-10467 is a vulnerability in Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, SD 820, and SD 820A.
How severe is CVE-2016-10467?
CVE-2016-10467 has a severity rating of 9.8 (critical).
Which software is affected by CVE-2016-10467?
CVE-2016-10467 affects Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, SD 820, and SD 820A.
How do I fix CVE-2016-10467?
To fix CVE-2016-10467, it is recommended to install the security patch provided by Qualcomm or update to a version of Android that includes the fix.
Where can I find more information about CVE-2016-10467?
More information about CVE-2016-10467 can be found at the following references: [1] [2] [3]