CVE-2016-5349

Description

The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure application's HLOS client. When secure applications inside Qualcomm Secure Execution Environment (QSEE) receive memory addresses from a high level operating system (HLOS) such as Linux Android, those address have previously been verified as belonging to HLOS memory space rather than QSEE memory space, but they were not verified to be from HLOS user space rather than kernel space. This lack of verification could lead to privilege escalation within the HLOS.

Category

5.5
CVSS
Severity: Medium
CVSS 3.0 •
CVSS 2.0 •
EPSS 0.12%
Vendor Advisory android.com Vendor Advisory qualcomm.com
Affected: Qualcomm, Inc. Qualcomm Snapdragon 800, 600, 400, 200
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2016-5349?
CVE-2016-5349 has been scored as a medium severity vulnerability.
How to fix CVE-2016-5349?
To fix CVE-2016-5349, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2016-5349 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2016-5349 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2016-5349?
CVE-2016-5349 affects Qualcomm, Inc. Qualcomm Snapdragon 800, 600, 400, 200.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.