CVE-2018-11847: Input Validation
Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt the QSEE kernel and compromise the whole TEE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables and Snapdragon Wired Infrastructure and Networking in versions IPQ8074, MDM9206, MDM9607, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCA8081, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 650/52, SD 820, SD 820A, SD 835, SD 8CX, SDM439 and SnapdragonHighMed2016
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11847?
CVE-2018-11847 has a high severity rating due to the potential for compromising the trusted execution environment.
How do I fix CVE-2018-11847?
To address CVE-2018-11847, update your affected Qualcomm device firmware to the latest version that includes fixes.
Which products are affected by CVE-2018-11847?
CVE-2018-11847 affects various Qualcomm products, including devices utilizing Snapdragon Auto, Connectivity, and Compute platforms.
What are the potential impacts of CVE-2018-11847?
CVE-2018-11847 can lead to the corruption of QSEE kernel memory, resulting in compromised system integrity.
Is there a specific patch for CVE-2018-11847?
Yes, Qualcomm has released patches for CVE-2018-11847, and users should apply them through official firmware updates.