PT-2020-9510 · Qualcomm · Snapdragon Wearables+15

Lacne Jiang

+1

·

Published

2020-02-07

·

Updated

2020-02-12

·

CVE-2019-14088

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon versions (affected versions not specified)
Description: The issue is related to a possible use after free problem while accessing the link pointer from device private data due to lack of resource protection. This affects various Qualcomm Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables, in specific chipsets such as APQ8009, MDM9206, MDM9207C, MDM9607, QCS605, SDM429W, SDX24, SM8150, and SXR1130.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14088
ZDI-20-199

Affected Products

Apq8009
Mdm9206
Mdm9207C
Mdm9607
Qcs605
Sdm429
Sdx24
Sm8150
Sxr1130
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Voice & Music
Snapdragon Wearables