CVE-2015-9185: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, in multiple Secure DEMUX functions (e.g., SDMXopensession, SDMXclosesession, SDMXsetsessioncfg), when parameter validation fails, an error code is written into a response buffer, without checking that response buffer length (rsplen) passed from HLOS is large enough to hold the response. If the buffer is at the end of a non-secure page followed by secured memory page, this can cause a secure memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9185?
CVE-2015-9185 is a vulnerability that affects Android devices with Qualcomm Snapdragon processors before the 2018-04-05 security patch level.
How severe is CVE-2015-9185?
CVE-2015-9185 has a severity rating of 9.8, which is considered critical.
Which devices are affected by CVE-2015-9185?
Android devices with Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear processors are affected.
How do I fix CVE-2015-9185?
To fix CVE-2015-9185, users should update their Android devices to the latest security patch level.
Where can I find more information about CVE-2015-9185?
More information about CVE-2015-9185 can be found in the security bulletins provided by Google and the Android Open Source Project.