First published: Mon Apr 01 2019(Updated: )
Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MSM8909W, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820A, SD 845 / SD 850, SD 855, SDM439, SDM630, SDM660, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9206 firmware | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9607 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
Qualcomm qm215 firmware | ||
Qualcomm qm215 | ||
qualcomm SD 425 firmware | ||
qualcomm SD 425 | ||
Qualcomm SD 439 firmware | ||
Qualcomm SD 439 | ||
Qualcomm SD 429 firmware | ||
Qualcomm SD 429 | ||
Qualcomm SD 450 firmware | ||
Qualcomm SD 450 | ||
qualcomm SD 625 firmware | ||
qualcomm SD 625 | ||
Qualcomm SD 632 firmware | ||
Qualcomm SD 632 | ||
qualcomm SD 636 firmware | ||
qualcomm SD 636 | ||
qualcomm SD 712 firmware | ||
qualcomm SD 712 | ||
qualcomm SD 710 firmware | ||
qualcomm SD 710 | ||
qualcomm SD 670 firmware | ||
qualcomm SD 670 | ||
qualcomm SD 820A firmware | ||
qualcomm SD 820A | ||
qualcomm SD 845 firmware | ||
qualcomm SD 845 | ||
qualcomm SD 850 firmware | ||
qualcomm SD 850 | ||
qualcomm SD 855 firmware | ||
qualcomm SD 855 | ||
qualcomm SDM439 firmware | ||
qualcomm SDM439 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
qualcomm SDM660 firmware | ||
qualcomm SDM660 | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13920 is rated as high severity due to the potential exploitation of a use-after-free vulnerability.
To fix CVE-2018-13920, update your device firmware to the latest version provided by Qualcomm or the device manufacturer.
CVE-2018-13920 affects several Qualcomm devices including MDM9206, MDM9607, and various Snapdragon models.
The impact of CVE-2018-13920 can lead to potential system crashes or arbitrary code execution due to improper handling of hrtimers.
Device manufacturers and Qualcomm are responsible for addressing CVE-2018-13920 by releasing firmware updates to remediate the vulnerability.