CVE-2019-10485: High severity android vulnerability
Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SnapdragonHighMed2016, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10485?
The severity of CVE-2019-10485 is classified as high due to its potential to cause an infinite loop during data decompression, leading to a system overrun.
How do I fix CVE-2019-10485?
To fix CVE-2019-10485, apply the latest firmware updates from Qualcomm for the affected Snapdragon products.
Which devices are affected by CVE-2019-10485?
CVE-2019-10485 affects various Snapdragon devices across automotive, consumer IoT, industrial IoT, and mobile platforms that utilize the APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, and several other Snapdragon series chipsets.
What type of vulnerability is CVE-2019-10485?
CVE-2019-10485 is a security vulnerability related to an infinite loop in the decoding of compressed data.
Is CVE-2019-10485 being actively exploited?
As of the latest reports, there is no evidence suggesting that CVE-2019-10485 is actively being exploited in the wild.