### [CVE-2016-5863](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5863) ![](https://img.shields.io/static/v1?label=Product&message=All%20Qualcomm%20products&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=Android%20for%20MSM%2C%20Firefox%20OS%20for%20MSM%2C%20QRD%20Android%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Validation%20of%20Array%20Index%20in%20USB&color=brightgreen) ### Description In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses. ### POC #### Reference No PoCs from references. #### Github - https://github.com/jiayy/android_vuln_poc-exp