CVE-2019-10506: Input Validation
While processing QCANL80211VENDORSUBCMDAVOIDFREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10506?
The severity of CVE-2019-10506 is high with a severity value of 7.8.
What is the affected software for CVE-2019-10506?
The affected software for CVE-2019-10506 includes Qualcomm Mdm9206 Firmware, Qualcomm Qcs605 Firmware, Qualcomm Sd 600 Firmware, Qualcomm Sd 625 Firmware, Qualcomm Sd 636 Firmware, Qualcomm Sd 665 Firmware, Qualcomm Sd 712 Firmware, Qualcomm Sd 710 Firmware, Qualcomm Sd 670 Firmware, Qualcomm Sd 730 Firmware, Qualcomm Sd 820a Firmware, Qualcomm Sd 835 Firmware, Qualcomm Sd 845 Firmware, Qualcomm Sd 850 Firmware, Qualcomm Sd 855 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm660 Firmware, Qualcomm Sdx24 Firmware.
Is Qualcomm Mdm9206 vulnerable to CVE-2019-10506?
No, Qualcomm Mdm9206 is not vulnerable to CVE-2019-10506.
Are Qualcomm Sd 670 devices vulnerable to CVE-2019-10506?
No, Qualcomm Sd 670 devices are not vulnerable to CVE-2019-10506.
How can I fix CVE-2019-10506?
To fix CVE-2019-10506, apply the necessary security patches provided by Qualcomm.