Junglewise Threat Intelligence

CVE-2016-8411: Google Android buffer overflow in QMI QOS TLV processing

CVE-2016-8411 · Severity: critical · CVSS 9.8 · Published 2017-01-27

Technologies: Google Android. Vendors: Google.

Executive brief

A critical security vulnerability exists in Android devices that use certain Qualcomm components for network communication. This flaw could allow a remote attacker to disrupt the device or potentially gain unauthorized access to sensitive data. If exploited, it could lead to a total compromise of the device, requiring a full system reinstallation to recover.

Technical details

A buffer overflow vulnerability exists in the Android kernel-space component responsible for processing Qualcomm MSM Interface (QMI) Quality of Service (QOS) Type-Length-Value (TLV) structures. The flaw is located in the 'qmi_qos_srvc.c' file. An attacker can exploit this by sending specially crafted QMI messages, leading to memory corruption. Given its location in device-specific code, successful exploitation could enable arbitrary code execution within the context of the kernel. This vulnerability was addressed in the December 2016 Android Security Bulletin.

Affected products

  • Google Android Versions containing qmi_qos_srvc.c; up to 7.1.1

Timeline

  • 2016-11-07: other: Partners notified of the vulnerability
  • 2016-12-05: patched: Security bulletin and patches released by Google
  • 2017-01-27: advisory: NVD advisory published

References

Related threats