CVE-2016-10237
Last modified
CVE-2016-10237 is a vulnerability of currently unknown severity. If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases from CAF using the Linux kernel, the TA would not detect an issue and it would be treated as secure memory.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases from CAF using the Linux kernel, the TA would not detect an issue and it would be treated as secure memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
- http://www.securityfocus.com/bid/97334Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
- http://www.securityfocus.com/bid/97334Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10237?
How severe is CVE-2016-10237?
How do I fix CVE-2016-10237?
Are you affected by CVE-2016-10237?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
