CVE-2016-10239
Last modified
CVE-2016-10239 is a vulnerability of currently unknown severity. In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer over-read vulnerability could potentially occur.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer over-read vulnerability could potentially occur.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
- http://www.securityfocus.com/bid/97334Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
- http://www.securityfocus.com/bid/97334Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10239?
How severe is CVE-2016-10239?
How do I fix CVE-2016-10239?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10233An elevation of privilege vulnerability in the Qualcomm vide…
- CVE-2016-10234An information disclosure vulnerability in the Qualcomm IPA …
- CVE-2016-10235A denial of service vulnerability in the Qualcomm WiFi drive…
- CVE-2016-10236An information disclosure vulnerability in the Qualcomm USB …
- CVE-2016-10237If shared content protection memory were passed as the secur…
- CVE-2016-10238In QSEE in all Android releases from CAF using the Linux ker…
- CVE-2016-1024Adobe Flash Player before 18.0.0.343 and 19.x through 21.x b…8.8
- CVE-2016-10242A time-of-check time-of-use race condition could potentially…
- CVE-2016-10243TeX Live allows remote attackers to execute arbitrary comman…
- CVE-2016-10244The parse_charstrings function in type1/t1load.c in FreeType…
- CVE-2016-10245Insufficient sanitization of the query parameter in template…
- CVE-2016-10246Buffer overflow in the main function in jstest_main.c in Muj…5.5
Are you affected by CVE-2016-10239?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
