CVE-2016-3904: High severity Google Android vulnerability
An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30311977. References: Qualcomm QC-CR#1050455.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need before this issue can be exploited?
Exploitation is local and requires user interaction. The issue is rated High because the attacker must first compromise a privileged process.
What level of access could successful exploitation provide?
A local malicious application could execute arbitrary code in the context of the kernel, resulting in high impacts to confidentiality, integrity, and availability.
Which Android releases are affected?
Android releases before 2016-11-05 are affected, according to the available vulnerability data.
Is a fix available?
Yes. A patch is available; the Android security bulletin dated 2016-11-01 and the referenced Qualcomm kernel commit provide remediation information.