In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, there is a TOCTOU vulnerability in the input validation for bulletin_board_read syscall. A pointer dereference is being validated without promising the pointer hasn't been changed by the HLOS program.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Qualcomm
Subscribe
|
Sd 425
Subscribe
Sd 425 Firmware
Subscribe
Sd 430
Subscribe
Sd 430 Firmware
Subscribe
Sd 450
Subscribe
Sd 450 Firmware
Subscribe
Sd 625
Subscribe
Sd 625 Firmware
Subscribe
Sd 650
Subscribe
Sd 650 Firmware
Subscribe
Sd 652
Subscribe
Sd 652 Firmware
Subscribe
Sd 820
Subscribe
Sd 820 Firmware
Subscribe
Sd 820a
Subscribe
Sd 820a Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-1621 | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, there is a TOCTOU vulnerability in the input validation for bulletin_board_read syscall. A pointer dereference is being validated without promising the pointer hasn't been changed by the HLOS program. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qualcomm
Published:
Updated: 2024-09-16T23:46:04.024Z
Reserved: 2017-08-16T00:00:00.000Z
Link: CVE-2016-10439
No data.
Status : Modified
Published: 2018-04-18T14:29:11.403
Modified: 2024-11-21T02:44:00.787
Link: CVE-2016-10439
No data.
OpenCVE Enrichment
No data.
EUVD