CVE-2018-11864: Input Validation
Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in versions IPQ8074, MDM9150, MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCA8081, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11864?
CVE-2018-11864 is considered a high severity vulnerability due to its potential impact on the confidentiality of sensitive data.
How do I fix CVE-2018-11864?
To mitigate CVE-2018-11864, update the affected Qualcomm Snapdragon firmware to the latest version provided by your device manufacturer.
Which devices are affected by CVE-2018-11864?
CVE-2018-11864 affects various Qualcomm Snapdragon platforms including Snapdragon Auto, Snapdragon Compute, and several others as listed in the advisory.
What types of attacks can exploit CVE-2018-11864?
Exploitation of CVE-2018-11864 may allow an attacker to read sensitive data from the high-level operating system due to improper memory management.
Is CVE-2018-11864 being actively exploited?
As of now, there are no confirmed reports of active exploitation for CVE-2018-11864, but it is advisable to apply security updates promptly.