PT-2020-9114 · Qualcomm · Snapdragon Industrial Iot+6
Published
2020-04-16
·
Updated
2020-04-22
·
CVE-2019-10622
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Snapdragon Auto versions APQ8009 through SM8250
Snapdragon Compute versions APQ8009 through SM8250
Snapdragon Consumer Electronics Connectivity versions APQ8009 through SM8250
Snapdragon Consumer IOT versions APQ8009 through SM8250
Snapdragon Industrial IOT versions APQ8009 through SM8250
Snapdragon Mobile versions APQ8009 through SM8250
Snapdragon Wired Infrastructure and Networking versions APQ8009 through SM8250
Description
Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace. This issue affects various Snapdragon products.
Recommendations
For all affected versions, consider implementing a check for the size of the payload received from userspace to prevent out of bound memory access.
As a temporary workaround, consider restricting access to the ADSP message parsing functionality until a patch is available.
Avoid using the
payload variable in the affected code until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Electronics Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Wired Infrastructure/Networking