CVE-2018-11970: High severity android vulnerability
TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 636, SD 712 / SD 710 / SD 670, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11970?
The severity of CVE-2018-11970 is high with a severity value of 7.
Which products are affected by CVE-2018-11970?
Google Android, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9607 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Mdm9655 Firmware, Qualcomm Qcs605 Firmware, Qualcomm Sd 410 Firmware, Qualcomm Sd 412 Firmware, Qualcomm Sd 636 Firmware, Qualcomm Sd 712 Firmware, Qualcomm Sd 710 Firmware, Qualcomm Sd 670 Firmware, Qualcomm Sd 845 Firmware, Qualcomm Sd 850 Firmware, Qualcomm Sd 8cx Firmware, Qualcomm Sda660 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm660 Firmware, Qualcomm Sxr1130 Firmware are affected by CVE-2018-11970.
How can I fix CVE-2018-11970?
Apply the necessary security patches provided by Google and Qualcomm for the affected products.
Where can I find more information about CVE-2018-11970?
You can find more information about CVE-2018-11970 in the Qualcomm Product Security Bulletins and the Android Security Bulletins.
What is the vulnerability description of CVE-2018-11970?
TZ App dynamic allocations are not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 636, SD 712 / SD 710 / SD 670, SD 845, SD 850, SD 8cx, SDA660, SDM630, SDM660, SXR1130, which allows an attacker to execute arbitrary code.