CVE-2018-11930: Integer Underflow
Improper input validation on input data which is used to locate and copy the additional IEs in WLAN function can lead to potential integer truncation issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCS605, Qualcomm 215, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 675, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24, SM7150
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11930?
CVE-2018-11930 has a medium severity level due to its potential for integer truncation issues.
How do I fix CVE-2018-11930?
To fix CVE-2018-11930, update your device's firmware to the latest version as provided by the manufacturer.
Which products are affected by CVE-2018-11930?
CVE-2018-11930 affects various Qualcomm Snapdragon devices across mobile and IoT sectors.
What causes CVE-2018-11930 vulnerability?
CVE-2018-11930 is caused by improper input validation in the WLAN function of Qualcomm's chipset.
Is CVE-2018-11930 exploitable remotely?
CVE-2018-11930 could potentially be exploited remotely if an attacker can access the affected WLAN function.