CVE-2018-13909: Race Condition
Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulting in unexpected behavior in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, Qualcomm 215, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-13909.
What is the severity level of CVE-2018-13909?
CVE-2018-13909 has a severity level of high.
Which products or software are affected by CVE-2018-13909?
CVE-2018-13909 affects Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobil.
Are there any recommended references for CVE-2018-13909?
Yes, you can refer to the following links for more information: [link1](https://source.android.com/docs/security/bulletin/2019-05-01/#asterisk), [link2](https://source.android.com/docs/security/bulletin/2019-05-01), [link3](https://www.qualcomm.com/company/product-security/bulletins).
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2018-13909?
The CWE ID associated with CVE-2018-13909 is CWE-362.