CVE-2016-5858: Google Android
Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.
Affected products
- Google Android: any version
Published 2017-08-16. Last modified 2026-06-17.