CVE-2018-13902: Out-of-bounds Read
Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decoding XTRA file in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SDX20, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13902?
CVE-2018-13902 has a high severity rating due to the potential for out of bounds memory access leading to unexpected behavior.
How do I fix CVE-2018-13902?
To fix CVE-2018-13902, apply the security updates provided by the manufacturer for affected Qualcomm firmware or devices.
What systems are affected by CVE-2018-13902?
CVE-2018-13902 affects multiple Qualcomm products including Snapdragon Auto, Snapdragon Compute, and various Snapdragon IoT and mobile platforms.
What are the consequences of exploiting CVE-2018-13902?
Exploiting CVE-2018-13902 could lead to potential information leakage or unexpected device behavior due to improper memory access.
Is CVE-2018-13902 associated with any particular firmware versions?
Yes, CVE-2018-13902 primarily affects certain firmware versions of Qualcomm MDM and Snapdragon products.