CVE-2018-13924: Buffer Overflow
Lack of check to prevent the buffer length taking negative values can lead to stack overflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9150, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCA6174A, QCA8081, QCS404, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SDX20, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13924?
CVE-2018-13924 has a severity rating that may allow local attackers to exploit it to cause a stack overflow.
How do I fix CVE-2018-13924?
To mitigate CVE-2018-13924, update the affected Qualcomm firmware or software to the latest patched version.
What devices are affected by CVE-2018-13924?
CVE-2018-13924 affects multiple Qualcomm products, including Android devices running vulnerable firmware.
Can CVE-2018-13924 be exploited remotely?
CVE-2018-13924 is more likely to be exploited locally rather than remotely, requiring access to the device.
Does CVE-2018-13924 affect all Snapdragon products?
CVE-2018-13924 affects various Snapdragon products but not all of them are vulnerable, so specific identification is required.