CVE-2019-10488: Null Pointer Dereference
Null pointer dereference can occur while parsing invalid chunks while playing the nonstandard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCA6574AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10488?
The severity of CVE-2019-10488 is classified as high due to the potential for exploitation through a null pointer dereference.
How do I fix CVE-2019-10488?
To fix CVE-2019-10488, ensure that you update your affected Qualcomm firmware or Android version to the latest security patch provided by the vendor.
What systems are affected by CVE-2019-10488?
CVE-2019-10488 affects various Qualcomm chips including the MDM9150, MDM9206, MDM9607, and several others listed in the advisory.
What impact does CVE-2019-10488 have on affected systems?
CVE-2019-10488 may allow attackers to cause a denial of service through a null pointer dereference, potentially crashing the system.
Is CVE-2019-10488 being actively exploited?
As of now, there is no public information indicating that CVE-2019-10488 is being actively exploited in the wild.