First published: Mon Feb 04 2019(Updated: )
Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9650, MDM9655, MSM8996AU, QCS605, SD 410/12, SD 615/16/SD 415, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SXR1130.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MDM9655 firmware | ||
Qualcomm MDM9655 firmware | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SD410 Firmware | ||
Qualcomm Snapdragon 410 | ||
Qualcomm SD 12 Firmware | ||
Qualcomm SD 12 Firmware | ||
Qualcomm SD615 Firmware | ||
Qualcomm Snapdragon 615 | ||
Qualcomm SD 16 Firmware | ||
Qualcomm SD 16 Firmware | ||
Qualcomm Snapdragon 415 Firmware | ||
Qualcomm Snapdragon 415 | ||
Qualcomm SD 675 Firmware | ||
Qualcomm Snapdragon 675 | ||
Qualcomm Snapdragon 712 Firmware | ||
Qualcomm Snapdragon 712 | ||
Qualcomm SD710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SD 670 | ||
Qualcomm SDM670 | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SD 8cx Firmware | ||
Qualcomm Snapdragon 8cx | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11932 is critical with a CVSS score of 9.1.
Qualcomm MDM9650 Firmware, Qualcomm MDM9655 Firmware, Qualcomm MSM8996AU Firmware, Qualcomm QCS605 Firmware, Qualcomm SD 410 Firmware, Google Android, Qualcomm SD 16 Firmware, Qualcomm SD 415 Firmware, Qualcomm SD 675 Firmware, Qualcomm SD 712 Firmware, Qualcomm SD 710 Firmware, Qualcomm SD 670 Firmware, Qualcomm SD 820a Firmware, Qualcomm SD 835 Firmware, Qualcomm SD 845 Firmware, Qualcomm SD 850 Firmware, Qualcomm SD 8cx Firmware, Qualcomm SXR1130 Firmware.
CVE-2018-11932 allows for improper input validation, which can lead to read and write access to the secure subsystem from the HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Mobile.
The fix for CVE-2018-11932 is to apply the appropriate security patches provided by the software vendor or upgrade to a non-vulnerable version of the software.
Yes, you can find additional references for CVE-2018-11932 at the following links: [Link 1](https://source.android.com/docs/security/bulletin/2019-02-01/#asterisk), [Link 2](https://source.android.com/docs/security/bulletin/2019-02-01), [Link 3](http://www.securityfocus.com/bid/106845).