First published: Mon Feb 25 2019(Updated: )
Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Snapdragon Auto Firmware | ||
Qualcomm Snapdragon Auto | ||
Qualcomm Snapdragon Connectivity Firmware | ||
Qualcomm Snapdragon Connectivity | ||
Qualcomm Snapdragon Consumer Internet Of Things Firmware | ||
Qualcomm Snapdragon Consumer Internet Of Things | ||
Qualcomm Snapdragon Industrial Internet Of Things Firmware | ||
Qualcomm Snapdragon Industrial Internet Of Things | ||
Qualcomm Snapdragon Mobile Firmware | ||
Qualcomm Snapdragon Mobile | ||
Qualcomm Snapdragon Voice \& Music Firmware | ||
Qualcomm Snapdragon Voice \& Music | ||
Qualcomm Mdm9150 Firmware | ||
Qualcomm Mdm9150 | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
Qualcomm Mdm9607 Firmware | ||
Qualcomm Mdm9607 | ||
Qualcomm Mdm9640 Firmware | ||
Qualcomm Mdm9640 | ||
Qualcomm Mdm9650 Firmware | ||
Qualcomm Mdm9650 | ||
Qualcomm Msm8909w Firmware | ||
Qualcomm Msm8909w | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Qcs605 Firmware | ||
Qualcomm Qcs605 | ||
Qualcomm Sd 210 Firmware | ||
Qualcomm Sd 210 | ||
Qualcomm Sd 212 Firmware | ||
Qualcomm Sd 212 | ||
Qualcomm Sd 205 Firmware | ||
Qualcomm Sd 205 | ||
Qualcomm Sd 425 Firmware | ||
Qualcomm Sd 425 | ||
Qualcomm Sd 439 Firmware | ||
Qualcomm Sd 439 | ||
Qualcomm Sd 429 Firmware | ||
Qualcomm Sd 429 | ||
Qualcomm Sd 625 Firmware | ||
Qualcomm Sd 625 | ||
Qualcomm Sd 636 Firmware | ||
Qualcomm Sd 636 | ||
Qualcomm Sd 712 Firmware | ||
Qualcomm Sd 712 | ||
Qualcomm Sd 710 Firmware | ||
Qualcomm Sd 710 | ||
Qualcomm Sd 670 Firmware | ||
Qualcomm Sd 670 | ||
Qualcomm Sd 820 Firmware | ||
Qualcomm Sd 820 | ||
Qualcomm Sd 820a Firmware | ||
Qualcomm Sd 820a | ||
Qualcomm Sd 835 Firmware | ||
Qualcomm Sd 835 | ||
Qualcomm Sd 845 Firmware | ||
Qualcomm Sd 845 | ||
Qualcomm Sd 850 Firmware | ||
Qualcomm Sd 850 | ||
Qualcomm Sda660 Firmware | ||
Qualcomm Sda660 | ||
Qualcomm Sdm439 Firmware | ||
Qualcomm Sdm439 | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Qualcomm Sdx20 Firmware | ||
Qualcomm Sdx20 | ||
Qualcomm Sdx24 Firmware | ||
Qualcomm Sdx24 |
https://www.codeaurora.org/security-bulletin/2019/02/04/february-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-13912 is medium with a severity value of 5.5.
CVE-2018-13912 affects Qualcomm Snapdragon Auto Firmware, Qualcomm Snapdragon Connectivity Firmware, Qualcomm Snapdragon Consumer Internet Of Things Firmware, Qualcomm Snapdragon Industrial Internet Of Things Firmware, Qualcomm Snapdragon Mobile Firmware, and Qualcomm Snapdragon Voice & Music Firmware.
To fix CVE-2018-13912, it is recommended to apply the necessary security patches provided by Qualcomm.
The Common Weakness Enumeration (CWE) of CVE-2018-13912 is CWE-119.
More information about CVE-2018-13912 can be found at the Code Aurora security bulletin: https://www.codeaurora.org/security-bulletin/2019/02/04/february-2019-code-aurora-security-bulletin.