CVE-2016-10476: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, and SDX20, missing array index checks on app index in function qcriluimclearencryptedpin results in accessing addresses outside the bounds of the buffer when app index is too large.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10476?
The severity of CVE-2016-10476 is critical with a value of 9.8.
What is the impact of CVE-2016-10476?
CVE-2016-10476 can allow an attacker to execute arbitrary code on the affected device, leading to potential information disclosure, privilege escalation, or denial of service.
How does CVE-2016-10476 affect Qualcomm Snapdragon Mobile and Snapdragon Wear devices?
CVE-2016-10476 affects devices running Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835.
How can I fix the vulnerability CVE-2016-10476?
To fix the vulnerability CVE-2016-10476, it is recommended to update the affected Android devices to at least the 2018-04-05 security patch level or later.
Where can I find more information about CVE-2016-10476?
More information about CVE-2016-10476 can be found at the following references: [1](http://www.securityfocus.com/bid/103671), [2](https://source.android.com/security/bulletin/2018-04-01), [3](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).