CVE-2019-10484: Use After Free
Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated during previous command teardwon sequence in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8098, MSM8909W, Nicobar, QCS405, QCS605, SDA845, SDM660, SDM670, SDM710, SDM845, SDX24, SM6150, SM7150, SM8150, SM8250, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10484?
CVE-2019-10484 is classified as a serious vulnerability due to a use-after-free issue.
How do I fix CVE-2019-10484?
To fix CVE-2019-10484, update your devices with the latest security patches provided by Qualcomm or your device manufacturer.
What causes the vulnerability CVE-2019-10484?
CVE-2019-10484 is caused by command destructors accessing a deallocated response buffer during the command teardown sequence.
Which devices are affected by CVE-2019-10484?
CVE-2019-10484 affects multiple Qualcomm firmware and devices including various Snapdragon products.
Is CVE-2019-10484 being actively exploited?
As of now, there are no reports confirming active exploitation of CVE-2019-10484.