PT-2020-9476 · Qualcomm · Sdm439+27

Published

2020-02-07

·

Updated

2020-02-10

·

CVE-2019-14049

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon Auto versions prior to the fixed version Qualcomm Snapdragon Compute versions prior to the fixed version Qualcomm Snapdragon Consumer Electronics Connectivity versions prior to the fixed version Qualcomm Snapdragon Consumer IOT versions prior to the fixed version Qualcomm Snapdragon Industrial IOT versions prior to the fixed version Qualcomm Snapdragon Mobile versions prior to the fixed version Qualcomm Snapdragon Voice & Music versions prior to the fixed version APQ8017 version prior to the fixed version APQ8053 version prior to the fixed version APQ8096AU version prior to the fixed version MDM9206 version prior to the fixed version MDM9207C version prior to the fixed version MDM9607 version prior to the fixed version MDM9640 version prior to the fixed version MSM8953 version prior to the fixed version QCN7605 version prior to the fixed version QCS605 version prior to the fixed version SC8180X version prior to the fixed version SDA845 version prior to the fixed version SDM429 version prior to the fixed version SDM439 version prior to the fixed version SDM450 version prior to the fixed version SDM632 version prior to the fixed version SDX20 version prior to the fixed version SDX24 version prior to the fixed version SDX55 version prior to the fixed version SM8150 version prior to the fixed version SXR1130 version prior to the fixed version
Description: A Stage-2 fault occurs when writing to an ION system allocation assigned to non-HLOS memory, which is non-standard. This issue affects various Qualcomm Snapdragon products, including Auto, Compute, Consumer Electronics Connectivity, Consumer IOT, Industrial IOT, Mobile, and Voice & Music, as well as specific chipsets such as APQ8017, APQ8053, and others.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14049

Affected Products

Apq8017
Apq8053
Apq8096Au
Mdm9206
Mdm9207C
Mdm9607
Mdm9640
Msm8953
Qcn7605
Qcs605
Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Consumer Electronics Connectivity
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Mobile
Qualcomm Snapdragon Voice & Music
Sc8180X
Sda845
Sdm429
Sdm439
Sdm450
Sdm632
Sdx20
Sdx24
Sdx55
Sm8150
Sxr1130