CVE-2015-9138: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, when an RSA encryption operation is called, the ceutiltounsignedbin is invoked to convert the input buffer to unsigned binary. The ceutiltounsignedbin function, instead of operating on the size of the unsigned character buffer that is passed, operates on the address - i.e. operates on "c" instead of "c". Decrementing the address to check if it is less than zero means that the operation will always pass, since a pointer will never be less than zero, and may result in a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9138?
CVE-2015-9138 has been classified with a critical severity due to its potential impact on vulnerable devices.
How do I fix CVE-2015-9138?
To fix CVE-2015-9138, update your Android device or Qualcomm firmware to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2015-9138?
CVE-2015-9138 affects various Qualcomm Snapdragon SoCs, including models such as FSM9055, IPQ4019, MDM9206, and others prior to the specified security patches.
What type of vulnerability is CVE-2015-9138?
CVE-2015-9138 is a security vulnerability in the Qualcomm Snapdragon chipset affecting the Android operating system.
When was CVE-2015-9138 disclosed?
CVE-2015-9138 was disclosed on April 1, 2018, as part of Android's security bulletins.