CVE-2016-2454: Input Validation
Published May 9, 2016
·Updated
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
Affected Software
2 affected components
Google Android<=6.0.1
Google Nexus 5
Remediation
Patch Available
Event History
May 9, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2454?
CVE-2016-2454 has a high severity rating due to its potential to cause a denial of service leading to device reboot.
2
How do I fix CVE-2016-2454?
To fix CVE-2016-2454, update your Android device to a version released on or after May 1, 2016.
3
Which devices are affected by CVE-2016-2454?
CVE-2016-2454 affects Android devices prior to version 6.0.1 and specifically impacts Nexus 5 devices.
4
What type of attack does CVE-2016-2454 enable?
CVE-2016-2454 enables remote attackers to execute a denial of service attack through a crafted video file.
5
Is there a workaround for CVE-2016-2454?
There are no specific workarounds for CVE-2016-2454; the recommended action is to apply the relevant software update.