ZeroHour

CVE-2016-10439

CVSS 3.0
8.1 high
EPSS
<1%p54
Published
()
Modified
Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, there is a TOCTOU vulnerability in the input validation for bulletin_board_read syscall. A pointer dereference is being validated without promising the pointer hasn't been changed by the HLOS program.

Vendors
qualcomm
Products
sd 425 firmware, sd 430 firmware, sd 450 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware, sd 820 firmware, sd 820a firmware
Weakness
CWE-362, CWE-476
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.