CVE-2019-10497: Use After Free
Use after free issue occurs If another instance of open for voicesvc node has been called from application without closing the previous one. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10497?
CVE-2019-10497 has been rated as high severity due to the potential for exploitation in specific Qualcomm hardware.
How do I fix CVE-2019-10497?
To mitigate CVE-2019-10497, users should apply the latest firmware updates provided by Qualcomm for their affected devices.
What types of devices are affected by CVE-2019-10497?
CVE-2019-10497 impacts various Qualcomm platforms including automotive, consumer IoT, industrial IoT, and mobile devices.
What is a use after free vulnerability as seen in CVE-2019-10497?
A use after free vulnerability occurs when a program continues to use a pointer after the memory it points to has been freed, potentially leading to memory corruption.
How can I determine if my device is vulnerable to CVE-2019-10497?
You can determine if your device is vulnerable to CVE-2019-10497 by checking the device firmware version against the list of affected Qualcomm models.