PT-2020-9463 · Qualcomm · Qualcomm Snapdragon

Published

2020-07-30

·

Updated

2020-07-31

·

CVE-2019-14037

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon versions APQ8009 through SXR1130
Description: Close and bind operations done on a socket can lead to a Use-After-Free condition in various Qualcomm Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables.
Recommendations: For versions APQ8009 through SXR1130, consider disabling socket close and bind operations until a patch is available. Restrict access to vulnerable socket operations to minimize the risk of exploitation. Avoid using vulnerable socket functions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14037

Affected Products

Qualcomm Snapdragon