CVE-2016-10490: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, if a negative value is passed as argument "max" to qurtqdistatelocalnewhandlefromobj, an buffer overflow occurs, due to typecasting the signed integer to unsigned.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10490?
CVE-2016-10490 is a vulnerability in Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon devices.
What software is affected by CVE-2016-10490?
CVE-2016-10490 affects Qualcomm Snapdragon devices running Android before 2018-04-05 or earlier security patch level.
What is the severity of CVE-2016-10490?
CVE-2016-10490 has a severity rating of critical (9.8).
What is the Common Weakness Enumeration (CWE) ID for CVE-2016-10490?
The CWE ID for CVE-2016-10490 is 119, which corresponds to Improper Restriction of Operations within the Bounds of a Memory Buffer.
Where can I find more information about CVE-2016-10490?
You can find more information about CVE-2016-10490 at the following references: http://www.securityfocus.com/bid/103671, https://source.android.com/security/bulletin/2018-04-01, and https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk.