First published: Mon Apr 02 2018(Updated: )
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, in a QTEE syscall handler, an untrusted pointer dereference can occur.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Mdm9625 Firmware | ||
Google Android | ||
Qualcomm Sd 425 Firmware | ||
Qualcomm Sd 425 | ||
Qualcomm Sd 430 Firmware | ||
Qualcomm Sd 430 | ||
Qualcomm Sd 450 Firmware | ||
Qualcomm Sd 450 | ||
Qualcomm Sd 625 Firmware | ||
Qualcomm Sd 625 | ||
Qualcomm Sd 650 Firmware | ||
Qualcomm Sd 650 | ||
Qualcomm Sd 652 Firmware | ||
Qualcomm Sd 652 | ||
Qualcomm Sd 820a Firmware | ||
Qualcomm Sd 820a | ||
Qualcomm Sd 820 Firmware | ||
Qualcomm Sd 820 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9111 has a medium severity rating due to the potential for untrusted pointer dereference in the QTEE syscall handler.
To fix CVE-2015-9111, ensure your Android device or Qualcomm firmware is updated to the latest security patch level post April 5, 2018.
CVE-2015-9111 affects various Android devices and Qualcomm Snapdragon models including MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650, SD 820, and SD 820A.
Devices updated after April 2018 should not be at risk for CVE-2015-9111 as the vulnerability has been addressed in security patches.
The root cause of CVE-2015-9111 is an untrusted pointer dereference occurring in the QTEE syscall handler in certain Qualcomm chipsets.