CVE-2019-10490: Use After Free
Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, SDA660, SDA845, SDM450, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150, SM8250, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10490?
CVE-2019-10490 is rated as high severity due to the potential for exploitation leading to denial of service or arbitrary code execution.
How do I fix CVE-2019-10490?
To fix CVE-2019-10490, update to the latest firmware or software version provided by your device manufacturer that addresses this vulnerability.
Which products are affected by CVE-2019-10490?
CVE-2019-10490 affects a range of Qualcomm products including various Snapdragon and MDM chipsets used in mobile and IoT devices.
What causes the vulnerability in CVE-2019-10490?
CVE-2019-10490 is caused by a use-after-free issue occurring in the Xtra daemon during shutdown due to static object instances being freed incorrectly.
Is there any known exploit for CVE-2019-10490?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2019-10490, but the vulnerability remains a risk if not patched.