CVE-2015-9199: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile IPQ4019, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, SD 810, SD 820, and SD 820A, A non-secure region check is done while registering QSEE buffer address which is passed by HLOS but not while logging in the QSEE buffer, so corruption of dynamically protected secure region can occur if the non-secure buffer is changed between the time it's checked and when it's used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9199?
The severity of CVE-2015-9199 is critical.
Which devices are affected by CVE-2015-9199?
Qualcomm Snapdragon Automobile and Snapdragon Mobile IPQ4019, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, SD 810, SD 820, and SD 820A are affected by CVE-2015-9199.
What is the solution for CVE-2015-9199?
Apply the security patch level on Android 2018-04-05 or later, provided by Google or Qualcomm, depending on the affected device.
Where can I find more information about CVE-2015-9199?
You can find more information about CVE-2015-9199 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/103671), [Android Security Bulletin](https://source.android.com/security/bulletin/2018-04-01), [Android Security Bulletin Details](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).
What is the Common Weakness Enumeration (CWE) ID for CVE-2015-9199?
The Common Weakness Enumeration (CWE) ID for CVE-2015-9199 is 119.