CVE-2018-11931: Input Validation
Improper access to HLOS is possible while transferring memory to CPZ in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in versions MDM9150, MDM9206, MDM9607, MDM9650, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11931?
CVE-2018-11931 is rated as a high severity vulnerability due to improper access control.
How do I fix CVE-2018-11931?
To fix CVE-2018-11931, update the affected Qualcomm firmware to the latest version provided by the manufacturer.
What are the potential impacts of CVE-2018-11931?
CVE-2018-11931 could allow attackers to access sensitive data or execute arbitrary code on affected devices.
Which devices are affected by CVE-2018-11931?
CVE-2018-11931 affects various Snapdragon chips including but not limited to MDM9150, MDM9206, and MDM9607.
Is there a workaround for CVE-2018-11931?
Currently, the best mitigation for CVE-2018-11931 is to apply the firmware patches released by Qualcomm.