First published: Mon Aug 05 2019(Updated: )
Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 820, SD 820A, SDM439
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | ||
Qualcomm Mdm9607 | ||
Qualcomm Msm8909w Firmware | ||
Qualcomm Msm8909w | ||
Google Android | ||
Qualcomm Qualcomm 215 | ||
Qualcomm Sd 210 Firmware | ||
Qualcomm Sd 210 | ||
Qualcomm Sd 212 Firmware | ||
Qualcomm Sd 212 | ||
Qualcomm Sd 205 Firmware | ||
Qualcomm Sd 205 | ||
Qualcomm Sd 425 Firmware | ||
Qualcomm Sd 425 | ||
Google Android | ||
Google Android | ||
Qualcomm Sd 430 Firmware | ||
Google Android | ||
Google Android | ||
Qualcomm Sd 435 | ||
Qualcomm Sd 439 Firmware | ||
Qualcomm Sd 439 | ||
Qualcomm Sd 429 Firmware | ||
Qualcomm Sd 429 | ||
Qualcomm Sd 450 Firmware | ||
Qualcomm Sd 450 | ||
Qualcomm Sd 625 Firmware | ||
Qualcomm Sd 625 | ||
Qualcomm Sd 632 Firmware | ||
Qualcomm Sd 632 | ||
Google Android | ||
Google Android | ||
Qualcomm Sd 820a Firmware | ||
Qualcomm Sd 820a | ||
Qualcomm Sdm439 Firmware | ||
Qualcomm Sdm439 |
https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-10492.
This vulnerability affects Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 820, SD 820A, SDM439.
The severity of CVE-2019-10492 is critical with a CVSS score of 7.8.
To fix this vulnerability, it is recommended to apply the necessary security patches provided by Qualcomm.
You can find more information about this vulnerability in the following references: [Link 1](https://source.codeaurora.org/quic/le/kernel/lk/commit/?id=960f533d9b0ad6a54fede75450dba67ffe965d4e), [Link 2](https://source.android.com/docs/security/bulletin/2019-08-01), [Link 3](https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin).