CVE-2015-9111: Null Pointer Dereference
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, in a QTEE syscall handler, an untrusted pointer dereference can occur.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9111?
CVE-2015-9111 has a medium severity rating due to the potential for untrusted pointer dereference in the QTEE syscall handler.
How do I fix CVE-2015-9111?
To fix CVE-2015-9111, ensure your Android device or Qualcomm firmware is updated to the latest security patch level post April 5, 2018.
Which devices are affected by CVE-2015-9111?
CVE-2015-9111 affects various Android devices and Qualcomm Snapdragon models including MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650, SD 820, and SD 820A.
Is CVE-2015-9111 still a concern for devices updated after April 2018?
Devices updated after April 2018 should not be at risk for CVE-2015-9111 as the vulnerability has been addressed in security patches.
What is the root cause of CVE-2015-9111?
The root cause of CVE-2015-9111 is an untrusted pointer dereference occurring in the QTEE syscall handler in certain Qualcomm chipsets.