CVE-2016-5863: Google Android

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.

Affected products

Published 2017-08-16. Last modified 2026-06-17.