CVE-2019-10501: Use After Free
Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10501?
CVE-2019-10501 has a medium severity rating as it involves a use-after-free issue due to improper input validation.
How do I fix CVE-2019-10501?
To fix CVE-2019-10501, it is recommended to update to the latest firmware version provided by Qualcomm.
Which devices are affected by CVE-2019-10501?
CVE-2019-10501 affects devices using Snapdragon Auto, Compute, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables firmware.
What kind of issue is reported in CVE-2019-10501?
CVE-2019-10501 reports a use-after-free vulnerability stemming from insufficient input validation in the volume listener library.
Is there a workaround for CVE-2019-10501?
There are no known workarounds for CVE-2019-10501, and the best course of action is to apply the necessary firmware updates.