VYPR
Medium severity5.5NVD Advisory· Published Jun 13, 2017· Updated May 13, 2026

CVE-2016-10335

CVE-2016-10335

Description

A medium-severity vulnerability in Android's libtomcrypt, as used in CAF Linux kernel builds, could enable local information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A medium-severity vulnerability in Android's libtomcrypt, as used in CAF Linux kernel builds, could enable local information disclosure.

Vulnerability

In all Android releases from the Code Aurora Forum (CAF) using the Linux kernel, the libtomcrypt cryptographic library was updated to address an unspecified vulnerability. The flaw resides in the library's cryptographic implementation and is reachable when an affected Android device processes certain operations using libtomcrypt. All CAF-based Android releases are affected [1].

Exploitation

The attacker must have local access to the device and must be able to trigger processing of data by the vulnerable libtomcrypt routines. No authentication is required beyond local access, but user interaction may be needed to induce the library to process attacker-controlled data [1].

Impact

Successful exploitation could lead to local information disclosure. The attacker may be able to read sensitive data that was processed by libtomcrypt, potentially bypassing protections offered by the cryptographic library. The compromise is limited to information disclosure and does not grant code execution or privilege escalation [1].

Mitigation

The fix was released as part of the Android Security Bulletin for June 2017 [1]. Users should apply the security update provided by their device manufacturer. No workaround is available other than installing the patch.

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
  • Qualcomm, Inc./All Qualcomm productsv5
    Range: All Android releases from CAF using the Linux kernel

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.