VYPR
Unrated severityNVD Advisory· Published Apr 18, 2018· Updated Sep 17, 2024

CVE-2016-10459

CVE-2016-10459

Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 800, SD 810, and SD 820, during a call, memory exhaustion can occur.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A memory exhaustion vulnerability in Qualcomm Snapdragon chipsets during calls can lead to denial of service, patched in Android 2018-04-05 or earlier security patch level.

Vulnerability

CVE-2016-10459 is a memory exhaustion vulnerability in the Qualcomm components of Android, affecting the Snapdragon Mobile and Snapdragon Wear platforms. The issue occurs during a call and leads to memory exhaustion. Affected chipsets include MDM9206, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 800, SD 810, and SD 820. The vulnerability is fixed in Android security patch level 2018-04-05 or earlier [1].

Exploitation

An attacker must be able to initiate or participate in a call on an affected device. The exact prerequisites are not fully detailed in the available references, but the vulnerability can be triggered during normal call handling, potentially by network-based or local manipulation of call parameters to cause excessive memory allocation [1].

Impact

Successful exploitation leads to memory exhaustion, which can cause the device to become unresponsive or crash, resulting in a denial of service (DoS). No code execution or privilege escalation is described; the primary impact is on availability [1].

Mitigation

The vulnerability is addressed in the Android security patch level 2018-04-05 or earlier, as indicated in the April 2018 Android Security Bulletin. Users should ensure their devices have received the relevant OTA update or flashed the latest firmware from their vendor. No workaround is detailed [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Qualcomm, Inc./Snapdragon Mobile, Snapdragon Wearv5
    Range: MDM9206, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 800, SD 810, SD 820

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.