PT-2019-16319 · Qualcomm · Qualcomm Snapdragon Wired Infrastructure/Networking+8
Published
2019-07-25
·
Updated
2021-07-21
·
CVE-2019-2239
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon Auto versions MDM9150 through MDM9655
Qualcomm Snapdragon Compute versions MDM9150 through MDM9655
Qualcomm Snapdragon Connectivity versions MDM9150 through MDM9655
Qualcomm Snapdragon Consumer Electronics Connectivity versions MDM9150 through MDM9655
Qualcomm Snapdragon Consumer IOT versions MDM9150 through MDM9655
Qualcomm Snapdragon Industrial IOT versions MDM9150 through MDM9655
Qualcomm Snapdragon Mobile versions MDM9150 through MDM9655
Qualcomm Snapdragon Voice & Music versions MDM9150 through MDM9655
Qualcomm Snapdragon Wired Infrastructure and Networking versions MDM9150 through MDM9655
Description
The issue is related to missing sanity checks in the layout, which can lead to SUI Corruption or Denial of Service. This affects various Qualcomm Snapdragon products, including Auto, Compute, Connectivity, Consumer Electronics Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wired Infrastructure and Networking.
Recommendations
For Qualcomm Snapdragon Auto version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Compute version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Connectivity version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Consumer Electronics Connectivity version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Consumer IOT version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Industrial IOT version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Mobile version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Voice & Music version MDM9150, update to a version that includes the necessary sanity checks in the layout.
For Qualcomm Snapdragon Wired Infrastructure and Networking version MDM9150, update to a version that includes the necessary sanity checks in the layout.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Consumer Electronics Connectivity
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Mobile
Qualcomm Snapdragon Voice & Music
Qualcomm Snapdragon Wired Infrastructure/Networking