CVE-2018-13912: Buffer Overflow
Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13912?
The severity of CVE-2018-13912 is medium with a severity value of 5.5.
Which software is affected by CVE-2018-13912?
CVE-2018-13912 affects Qualcomm Snapdragon Auto Firmware, Qualcomm Snapdragon Connectivity Firmware, Qualcomm Snapdragon Consumer Internet Of Things Firmware, Qualcomm Snapdragon Industrial Internet Of Things Firmware, Qualcomm Snapdragon Mobile Firmware, and Qualcomm Snapdragon Voice & Music Firmware.
How can I fix CVE-2018-13912?
To fix CVE-2018-13912, it is recommended to apply the necessary security patches provided by Qualcomm.
What is the Common Weakness Enumeration (CWE) of CVE-2018-13912?
The Common Weakness Enumeration (CWE) of CVE-2018-13912 is CWE-119.
Where can I find more information about CVE-2018-13912?
More information about CVE-2018-13912 can be found at the Code Aurora security bulletin: https://www.codeaurora.org/security-bulletin/2019/02/04/february-2019-code-aurora-security-bulletin.