CVE-2016-10389: Google Android
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.
Affected products
- Google Android: any version
Published 2017-08-18. Last modified 2026-06-17.