CVE-2016-10484: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, and SDX20, if a RPMB listener is registered with a very small buffer size, the calculation of the maximum transfer size for read and write operations may underflow, resulting in buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10484?
CVE-2016-10484 is a vulnerability in Android devices using Qualcomm Snapdragon chipsets, allowing remote attackers to execute arbitrary code.
How severe is CVE-2016-10484?
CVE-2016-10484 has a severity rating of 9.8 (critical).
Which devices are affected by CVE-2016-10484?
Devices running Android with Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear chipsets are affected.
How can I fix CVE-2016-10484?
To fix CVE-2016-10484, update your Android device to a version released after April 5, 2018, or apply the corresponding security patch from Qualcomm.
Where can I find more information about CVE-2016-10484?
You can find more information about CVE-2016-10484 on the official Android security bulletin for April 2018.