CVE-2016-7990
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://security.samsungmobile.com/smrupdate.html#SMR-AUG-2016
References
CWEs
CWE-190 CWE-388
Verify integrity in audit chain (admin only). AS-IS.