{"api_version":"1","generated_at":"2026-07-23T03:40:46+00:00","cve":"CVE-2016-5349","urls":{"html":"https://cve.report/CVE-2016-5349","api":"https://cve.report/api/cve/CVE-2016-5349.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-5349","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-5349"},"summary":{"title":"CVE-2016-5349","description":"The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure application's HLOS client. When secure applications inside Qualcomm Secure Execution Environment (QSEE) receive memory addresses from a high level operating system (HLOS) such as Linux Android, those address have previously been verified as belonging to HLOS memory space rather than QSEE memory space, but they were not verified to be from HLOS user space rather than kernel space. This lack of verification could lead to privilege escalation within the HLOS.","state":"PUBLISHED","assigner":"qualcomm","published_at":"2017-04-06 19:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","Insufficient Memory Address Information to prevent Arbitrary Memory Access from QSEE Secure Applications"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.codeaurora.org/insufficient-memory-address-information-prevent-arbitrary-memory-access-qsee-secure-applications-cve","name":"https://www.codeaurora.org/insufficient-memory-address-information-prevent-arbitrary-memory-access-qsee-secure-applications-cve","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Insufficient Memory Address Information to prevent Arbitrary Memory Access from QSEE Secure Applications (CVE-2016-5349) | Code Aurora","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/97364","name":"http://www.securityfocus.com/bid/97364","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Google Nexus Qualcomm TrustZone CVE-2016-5349 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.qualcomm.com/company/product-security/security-advisories","name":"https://www.qualcomm.com/company/product-security/security-advisories","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisories | Product Security | Qualcomm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://source.android.com/security/bulletin/2017-04-01","name":"https://source.android.com/security/bulletin/2017-04-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Android Security Bulletin—April 2017  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1038201","name":"http://www.securitytracker.com/id/1038201","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Android Multiple Flaws Let Users Deny Service, Obtain Potentially Sensitive Information, and Gain Elevated Privileges and Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-5349","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-5349","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Qualcomm, Inc.","product":"Qualcomm Snapdragon 800, 600, 400, 200","version":"affected All Android releases from CAF using the Linux kernel.","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"5349","vulnerable":"1","versionEndIncluding":"7.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T01:01:00.079Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.codeaurora.org/insufficient-memory-address-information-prevent-arbitrary-memory-access-qsee-secure-applications-cve"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://source.android.com/security/bulletin/2017-04-01"},{"name":"97364","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/97364"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.qualcomm.com/company/product-security/security-advisories"},{"name":"1038201","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1038201"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Qualcomm Snapdragon 800, 600, 400, 200","vendor":"Qualcomm, Inc.","versions":[{"status":"affected","version":"All Android releases from CAF using the Linux kernel."}]}],"datePublic":"2017-03-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure application's HLOS client. When secure applications inside Qualcomm Secure Execution Environment (QSEE) receive memory addresses from a high level operating system (HLOS) such as Linux Android, those address have previously been verified as belonging to HLOS memory space rather than QSEE memory space, but they were not verified to be from HLOS user space rather than kernel space. This lack of verification could lead to privilege escalation within the HLOS."}],"problemTypes":[{"descriptions":[{"description":"Insufficient Memory Address Information to prevent Arbitrary Memory Access from QSEE Secure Applications","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T09:57:01.000Z","orgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","shortName":"qualcomm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.codeaurora.org/insufficient-memory-address-information-prevent-arbitrary-memory-access-qsee-secure-applications-cve"},{"tags":["x_refsource_CONFIRM"],"url":"https://source.android.com/security/bulletin/2017-04-01"},{"name":"97364","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/97364"},{"tags":["x_refsource_CONFIRM"],"url":"https://www.qualcomm.com/company/product-security/security-advisories"},{"name":"1038201","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1038201"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","ID":"CVE-2016-5349","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Qualcomm Snapdragon 800, 600, 400, 200","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel."}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure application's HLOS client. When secure applications inside Qualcomm Secure Execution Environment (QSEE) receive memory addresses from a high level operating system (HLOS) such as Linux Android, those address have previously been verified as belonging to HLOS memory space rather than QSEE memory space, but they were not verified to be from HLOS user space rather than kernel space. This lack of verification could lead to privilege escalation within the HLOS."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Insufficient Memory Address Information to prevent Arbitrary Memory Access from QSEE Secure Applications"}]}]},"references":{"reference_data":[{"name":"https://www.codeaurora.org/insufficient-memory-address-information-prevent-arbitrary-memory-access-qsee-secure-applications-cve","refsource":"CONFIRM","url":"https://www.codeaurora.org/insufficient-memory-address-information-prevent-arbitrary-memory-access-qsee-secure-applications-cve"},{"name":"https://source.android.com/security/bulletin/2017-04-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/2017-04-01"},{"name":"97364","refsource":"BID","url":"http://www.securityfocus.com/bid/97364"},{"name":"https://www.qualcomm.com/company/product-security/security-advisories","refsource":"CONFIRM","url":"https://www.qualcomm.com/company/product-security/security-advisories"},{"name":"1038201","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1038201"}]}}}},"cveMetadata":{"assignerOrgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","assignerShortName":"qualcomm","cveId":"CVE-2016-5349","datePublished":"2017-04-06T19:00:00.000Z","dateReserved":"2016-06-09T00:00:00.000Z","dateUpdated":"2024-08-06T01:01:00.079Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-04-06 19:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","Insufficient Memory Address Information to prevent Arbitrary Memory Access from QSEE Secure Applications"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1.1","matchCriteriaId":"0F11609D-D1B4-4DD6-8CC7-A224344E1E67"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"5349","Ordinal":"1","Title":"CVE-2016-5349","CVE":"CVE-2016-5349","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"5349","Ordinal":"1","NoteData":"The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure application's HLOS client. When secure applications inside Qualcomm Secure Execution Environment (QSEE) receive memory addresses from a high level operating system (HLOS) such as Linux Android, those address have previously been verified as belonging to HLOS memory space rather than QSEE memory space, but they were not verified to be from HLOS user space rather than kernel space. This lack of verification could lead to privilege escalation within the HLOS.","Type":"Description","Title":"CVE-2016-5349"},{"CveYear":"2016","CveId":"5349","Ordinal":"2","NoteData":"2017-04-06","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"5349","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}