CVE-2015-9108: Input Validation
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, no address argument validation performed on calls to a QSEE syscall may lead to arbitrary read/write or NULL Pointer exception when calling a downstream function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9108?
CVE-2015-9108 is classified as a critical vulnerability that can lead to arbitrary read/write operations.
How do I fix CVE-2015-9108?
To fix CVE-2015-9108, update your device to the latest firmware version that includes the April 2018 security patch or later.
Which devices are affected by CVE-2015-9108?
CVE-2015-9108 affects various Qualcomm Snapdragon chipsets, including MDM9625, SD 425, 430, 450, 625, 650, 652, 820, and 820A models.
What are the potential impacts of CVE-2015-9108?
The potential impacts of CVE-2015-9108 include unauthorized access, data corruption, or system crashes due to improper input validation.
When was CVE-2015-9108 disclosed?
CVE-2015-9108 was disclosed on April 5, 2018, as part of the Android security bulletin.