CVE-2016-10389: Google Android

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.

Affected products

Published 2017-08-18. Last modified 2026-06-17.