CVE-2015-9146: Input Validation
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, SD 400, SD 800, SD 835, SD 845, SD 850, and SDX20, when QDI read, write, or ioctl are called, the passed-in pointer is not properly validated before accessing it for the delayed response.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9146?
CVE-2015-9146 is a vulnerability in Android before 2018-04-05 or earlier security patch levels on Qualcomm Snapdragon Mobile devices.
Which devices are affected by CVE-2015-9146?
Devices with Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, SD 400, SD 800, SD 835, SD 845, SD 850, and SDX20 are affected by CVE-2015-9146.
What is the severity of CVE-2015-9146?
CVE-2015-9146 has a severity rating of 9.8 (Critical).
How can I fix CVE-2015-9146?
Apply the security patch released by Google for Android on or after 2018-04-05.
Where can I find more information about CVE-2015-9146?
You can visit the following references for more information: [SecurityFocus](http://www.securityfocus.com/bid/103671), [Android Security Bulletin 2018-04-01](https://source.android.com/security/bulletin/2018-04-01), [Android Security Bulletin 2018-04-01 - Asterisk](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).