CVE-2016-10481: Critical severity android vulnerability
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 425, SD 600, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, and SDX20, if WLAN FW receives the WMISTASMPSPARAMCMDID ioctl in not-associated state, when the virtual channel handle is not assigned, the code doesn't check for NULL virtual channel handle, so an assert occurs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10481?
The severity of CVE-2016-10481 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2016-10481?
The affected software for CVE-2016-10481 includes Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 425, SD 600, SD 625, SD 650/52, SD 808, and more.
How do I fix CVE-2016-10481?
To fix CVE-2016-10481, update your Android device to a security patch level on or after 2018-04-05.
What is the Common Weakness Enumeration (CWE) for CVE-2016-10481?
The CWE for CVE-2016-10481 is CWE-17.
Where can I find more information about CVE-2016-10481?
You can find more information about CVE-2016-10481 on the SecurityFocus website and the Android Security Bulletin for April 2018.