CVE-2016-8463: High severity android vulnerability
A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-30786860. References: QC-CR#586855.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems are identified as affected?
Android devices using Kernel-3.10 or Kernel-3.18 are identified as affected. The issue is in the Qualcomm FUSE file system.
What does exploitation require?
An attacker needs to provide a specially crafted file and requires user interaction to trigger the issue, as indicated by the CVSS UI:R vector. No privileges are required.
What is the expected impact?
Successful exploitation can cause the affected device to hang or reboot. The reported impact is denial of service, with no confidentiality or integrity impact listed.
What should administrators do?
A patch is available. Apply the available vendor or Android security updates that address Android ID A-30786860.