CVE-2016-10498: Critical severity android vulnerability
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SDM630, SDM636, SDM660, and SnapdragonHighMed2016, stopping of the DTR prematurely causes micro kernel to be stuck. This can be triggered with a timing change injectable in RACH procedure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10498?
The severity of CVE-2016-10498 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2016-10498?
The affected software for CVE-2016-10498 includes Android versions before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SDM630, SDM636, SDM660, and Snapdragon.
How can I mitigate the vulnerability?
To mitigate the vulnerability, it is recommended to update to the latest security patch level for Android or apply the necessary security updates provided by the device manufacturer.
Where can I find more information about CVE-2016-10498?
More information about CVE-2016-10498 can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/103671), [Android Security Bulletin](https://source.android.com/security/bulletin/2018-04-01), and [Android Security Bulletin 2018-04-01](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).
What is the Common Weakness Enumeration (CWE) for CVE-2016-10498?
The Common Weakness Enumeration (CWE) for CVE-2016-10498 is CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection').