Vulnerability Description
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99465Third Party AdvisoryVDB Entry
- https://source.android.com/security/bulletin/2017-07-01PatchVendor Advisory
- https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=daf0acd54a6a80dIssue TrackingPatchThird Party Advisory
- http://www.securityfocus.com/bid/99465Third Party AdvisoryVDB Entry
- https://source.android.com/security/bulletin/2017-07-01PatchVendor Advisory
- https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=daf0acd54a6a80dIssue TrackingPatchThird Party Advisory
FAQ
What is CVE-2016-5863?
CVE-2016-5863 is a vulnerability with a CVSS score of 7.8 (HIGH). In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
How severe is CVE-2016-5863?
CVE-2016-5863 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5863?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android.