On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.
| Software | From | Fixed in |
|---|---|---|
| google / android | 4.2.2 | 4.2.2.x |
| google / android | 4.3 | 4.3.x |
| google / android | 4.3.1 | 4.3.1.x |
| google / android | 4.4 | 4.4.x |
| google / android | 4.4.1 | 4.4.1.x |
| google / android | 4.4.2 | 4.4.2.x |
| google / android | 4.4.3 | 4.4.3.x |
| google / android | 4.4.4 | 4.4.4.x |
| google / android | 5.0 | 5.0.x |
| google / android | 5.0.1 | 5.0.1.x |
| google / android | 5.0.2 | 5.0.2.x |
| google / android | 5.1 | 5.1.x |
| google / android | 5.1.0 | 5.1.0.x |
| google / android | 5.1.1 | 5.1.1.x |
| google / android | 6.0 | 6.0.x |
| google / android | 6.0.1 | 6.0.1.x |