CVE-2016-10493: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, NPA routines on the rootPD that handle resource requests remoted over QDI may not validate pointers passed from user space which may result in guest OS memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10493?
The severity of CVE-2016-10493 is critical with a severity value of 9.8.
Which software versions are affected by CVE-2016-10493?
Android before 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear devices are affected.
How can I fix CVE-2016-10493?
Apply the security patch level of 2018-04-05 or later on affected devices.
What is the Common Weakness Enumeration (CWE) for CVE-2016-10493?
The Common Weakness Enumeration (CWE) for CVE-2016-10493 is 119.
Where can I find more information about CVE-2016-10493?
You can find more information about CVE-2016-10493 at the following references: [1](http://www.securityfocus.com/bid/103671), [2](https://source.android.com/security/bulletin/2018-04-01), [3](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).