CVE-2015-9123: Infoleak
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, and SDX20, code to zeroize AES key could be compiled out by compiler which could potentially result in information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9123?
CVE-2015-9123 has been classified as a vulnerability that can potentially allow remote code execution.
How do I fix CVE-2015-9123?
To fix CVE-2015-9123, ensure your Android device is updated to the latest security patch level, specifically the version released after April 5, 2018.
Which devices are affected by CVE-2015-9123?
CVE-2015-9123 affects various Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoCs including MDM9206 and MDM9607 among others.
What products are vulnerable to CVE-2015-9123?
Products vulnerable to CVE-2015-9123 include Android devices and Qualcomm chipsets such as MDM9615, MSM8909W, and several Snapdragon series.
Is there a patch available for CVE-2015-9123?
Yes, a patch for CVE-2015-9123 is available in updates for Android released after the specified security bulletin date.