CVE-2018-5913: High severity android vulnerability
A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What are the potential risks of CVE-2018-5913?
CVE-2018-5913 can create a side channel that potentially leaks sensitive information due to the non-time constant function used.
Which devices are affected by CVE-2018-5913?
CVE-2018-5913 affects various Qualcomm Snapdragon devices across multiple platforms including mobile and IoT.
Is there an available patch for CVE-2018-5913?
Yes, Qualcomm has released patches to address CVE-2018-5913, and users should update their devices accordingly.
How can I find out if my device is impacted by CVE-2018-5913?
To determine if your device is affected by CVE-2018-5913, check for firmware updates from your manufacturer that address this vulnerability.
What steps should be taken if my device is vulnerable to CVE-2018-5913?
If your device is vulnerable to CVE-2018-5913, it is recommended to immediately apply the latest firmware updates provided by the manufacturer.