First published: Mon Apr 02 2018(Updated: )
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, SD 400, SD 425, SD 430, SD 450, SD 600, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, in the Diag User-PD command registration function, a length variable used during buffer allocation is not checked, so if it is very large, an integer overflow followed by a buffer overflow occurs.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9625 firmware | ||
Qualcomm MDM9625 | ||
Qualcomm MDM9635M firmware | ||
Qualcomm MDM9635M | ||
qualcomm mdm9640 firmware | ||
qualcomm MDM9640 | ||
qualcomm mdm9645 firmware | ||
qualcomm mdm9645 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9655 firmware | ||
Qualcomm MDM9655 | ||
qualcomm SD 400 firmware | ||
qualcomm SD 400 | ||
qualcomm SD 425 firmware | ||
qualcomm SD 425 | ||
Qualcomm SD 430 firmware | ||
Qualcomm SD 430 | ||
Qualcomm SD 450 firmware | ||
Qualcomm SD 450 | ||
qualcomm SD 600 firmware | ||
qualcomm SD 600 | ||
qualcomm sd 617 firmware | ||
Qualcomm QCA617 | ||
qualcomm SD 625 firmware | ||
qualcomm SD 625 | ||
qualcomm sd 650 firmware | ||
qualcomm sd 650 | ||
qualcomm sd 652 firmware | ||
qualcomm sd 652 | ||
qualcomm SD 800 firmware | ||
qualcomm SD 800 | ||
qualcomm SD 808 firmware | ||
qualcomm SD 808 | ||
qualcomm sd 810 firmware | ||
qualcomm sd 810 | ||
qualcomm SD 820 firmware | ||
qualcomm SD 820 | ||
qualcomm SD 835 firmware | ||
qualcomm SD 835 | ||
qualcomm SD 845 firmware | ||
qualcomm SD 845 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware | ||
qualcomm SD 850 firmware | ||
qualcomm SD 850 | ||
qualcomm SD 820A firmware | ||
qualcomm SD 820A | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9148 has a high severity rating due to its potential impact on the security of affected Android devices and Qualcomm chipsets.
To resolve CVE-2015-9148, update your device to the latest security patch provided by the manufacturer.
CVE-2015-9148 affects various models with Qualcomm Snapdragon chipsets, particularly those that haven't received security patches since April 2018.
CVE-2015-9148 refers to a vulnerability in Qualcomm's firmware that could allow a remote attacker to execute arbitrary code on the affected devices.
There is no known workaround for CVE-2015-9148 other than applying the appropriate security updates from device manufacturers.