CVE-2016-5862
published 2017-08-16CVE-2016-5862: When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is…
PriorityP425high7CVSS 3.0
AVLACHPRNUIRSUCHIHAH
EPSS
0.52%
40.7th percentile
When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a device restart after kernel crash occurs.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| qualcomm_inc | all_qualcomm_products | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-5862: Android Security Bulletin 2017-05-01
CVE: CVE-2016-5862
Severity: HIGH
References: A-35399803
QC-CR#1099607
vendor_android·2017-05-01·CVSS 7.0
CVE-2016-5862 [HIGH] CVE-2016-5862: Android Security Bulletin 2017-05-01
CVE: CVE-2016-5862
Severity: HIGH
References: A-35399803
QC-CR#1099607
Android Security Bulletin 2017-05-01
CVE: CVE-2016-5862
Severity: HIGH
References: A-35399803
QC-CR#1099607
GHSA
GHSA-9v9m-grrv-xcjm: When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type c
ghsa_unreviewed·2022-05-17
CVE-2016-5862 [HIGH] GHSA-9v9m-grrv-xcjm: When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type c
When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a device restart after kernel crash occurs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98194https://source.android.com/security/bulletin/2017-05-01https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=4199451e83729a3add781eeafaee32994ff65b04http://www.securityfocus.com/bid/98194https://source.android.com/security/bulletin/2017-05-01https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=4199451e83729a3add781eeafaee32994ff65b04
2017-08-16
Published