Detection of error condition without proper action in msm_ds2_dap_param_visualizer_control_get() (CVE-2016-5853)

Release Date:

April 17, 2017

Affected Projects:

Android for MSMFirefox OS for MSMQRD Android

Advisory ID:

QCIR-2017-00024-1

CVE ID(s):

CVE-2016-5853

Summary:

The following security vulnerabilities have been identified: CVE-2016-5853 The function msm_ds2_dap_param_visualizer_control_get() implements a sanity check to check if the length value is in the correct range. When processing this check and the length value is not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value.

Access Vector: Local
Security Risk: Medium
Access Vector: Local

Affected Versions:

All Android releases from CAF using the Linux kernel.

Patch:

We advise customers to apply the following patches:

Individual Patches
CVE-2016-5853:

Acknowledgement:

Qualcomm Innovation Center, Inc. (QuIC) thanks Seven Shen (Trend Micro Mobile Threat Research Team) for bringing this issue to QuIC’s attention.

Revisions:

Initial revision

Contact:

security-advisory@quicinc.com