Variable-length arrays vulnerability in libril/RilSapSocket.cpp in Telephony in Android 6.x and 7.0 before 2016-10-01

Variable-length arrays vulnerability in libril/RilSapSocket.cpp in Telephony in Android 6.x and 7.0 before 2016-10-01

CVE-2016-3922 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

libril/RilSapSocket.cpp in Telephony in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 relies on variable-length arrays, which allows attackers to gain privileges via a crafted application, aka internal bug 30202619.

Learn more about our Cis Benchmark Audit For Google Android.