← Back

CVE-2016-7989

nvd nist
Published: Oct 31, 2016Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar. This causes the Android runtime to continually crash, rendering the device unusable until a factory reset is performed, a subset of SVE-2016-6542.

Affected (16)

Products: Google: Android
1 product
Android
Configuration A
16 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Google
Version 4.2.2
Version 4.3.1
Version 4.3
Version 4.4.1
Version 4.4.2
Version 4.4.3
Version 4.4.4
Version 4.4
Version 5.0.1
Version 5.0.2
Version 5.0
Version 5.1.0
Version 5.1.1
Version 5.1
Version 6.0.1
Version 6.0
Running on/withPlatform Versions
Samsung
Galaxy S4
All versions
Samsung
Galaxy S4 Mini
All versions
Samsung
Galaxy S5
All versions
Samsung
Galaxy S6
All versions
Samsung
Galaxy S7
All versions

Related CWEs

References (4)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.