CVE-2016-11038: Buffer Overflow
An issue was discovered on Samsung mobile devices with software through 2016-04-05 (incorporating the Samsung Professional Audio SDK). The Jack audio service doesn't implement access control for shared memory, leading to arbitrary code execution or privilege escalation. The Samsung ID is SVE-2016-5953 (July 2016).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-11038?
CVE-2016-11038 is a vulnerability found on Samsung mobile devices with software through 2016-04-05 that allows arbitrary code execution or privilege escalation.
How severe is CVE-2016-11038?
CVE-2016-11038 has a severity rating of 9.8 out of 10.
Which Samsung devices are affected by CVE-2016-11038?
Samsung Galaxy Note 3, Samsung Galaxy Note 4, Samsung Galaxy Note Edge, Samsung Galaxy S5, Samsung Galaxy S6, and Samsung Galaxy S6 Edge are not affected by CVE-2016-11038.
How can CVE-2016-11038 be fixed?
To fix CVE-2016-11038, update your Samsung mobile device's software through the latest security update provided by Samsung.
Where can I find more information about CVE-2016-11038?
More information about CVE-2016-11038 can be found on the Samsung Mobile Security website at https://security.samsungmobile.com/securityUpdate.smsb.