CVE-2018-11940: Buffer Overflow
Lack of check in length before using memcpy in WLAN function can lead to OOB access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCS605, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24, SXR1130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11940?
CVE-2018-11940 has been categorized as a high severity vulnerability due to the potential for out-of-bounds access.
How do I fix CVE-2018-11940?
To fix CVE-2018-11940, it is recommended to update affected Qualcomm firmware and ensure software checks for proper length before using memcpy.
Which devices are affected by CVE-2018-11940?
CVE-2018-11940 impacts multiple devices using Snapdragon Auto, Compute, Consumer IOT, Industrial IOT, and Mobile platforms.
What type of vulnerability is CVE-2018-11940?
CVE-2018-11940 is an out-of-bounds (OOB) access vulnerability caused by inadequate length checks in memory operations.
Can CVE-2018-11940 be exploited remotely?
Yes, CVE-2018-11940 can potentially be exploited remotely, depending on the application's access and the network configuration.