CVE-2015-9148: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, SD 400, SD 425, SD 430, SD 450, SD 600, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, in the Diag User-PD command registration function, a length variable used during buffer allocation is not checked, so if it is very large, an integer overflow followed by a buffer overflow occurs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9148?
CVE-2015-9148 has a high severity rating due to its potential impact on the security of affected Android devices and Qualcomm chipsets.
How do I fix CVE-2015-9148?
To resolve CVE-2015-9148, update your device to the latest security patch provided by the manufacturer.
Which devices are affected by CVE-2015-9148?
CVE-2015-9148 affects various models with Qualcomm Snapdragon chipsets, particularly those that haven't received security patches since April 2018.
What is the exploit type referenced in CVE-2015-9148?
CVE-2015-9148 refers to a vulnerability in Qualcomm's firmware that could allow a remote attacker to execute arbitrary code on the affected devices.
Is there a known workaround for CVE-2015-9148?
There is no known workaround for CVE-2015-9148 other than applying the appropriate security updates from device manufacturers.