First published: Mon Sep 30 2019(Updated: )
While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm QCA9377 Firmware | ||
Qualcomm QCA9377 Firmware | ||
Qualcomm QCA9379 | ||
Qualcomm QCA9379 | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SD600 Firmware | ||
Qualcomm Snapdragon 600 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SDM636 Firmware | ||
Qualcomm Snapdragon 636 | ||
Qualcomm Snapdragon 665 | ||
Qualcomm Snapdragon 665 | ||
Qualcomm SD 675 Firmware | ||
Qualcomm Snapdragon 675 | ||
Qualcomm Snapdragon 712 Firmware | ||
Qualcomm Snapdragon 712 | ||
Qualcomm SD710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SD 670 | ||
Qualcomm SDM670 | ||
Qualcomm SD 730 Firmware | ||
Qualcomm Snapdragon 730 | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SD855 Firmware | ||
Qualcomm SD855 Firmware | ||
Qualcomm SDM630 | ||
Qualcomm SDM630 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 |
https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-10506 is high with a severity value of 7.8.
The affected software for CVE-2019-10506 includes Qualcomm Mdm9206 Firmware, Qualcomm Qcs605 Firmware, Qualcomm Sd 600 Firmware, Qualcomm Sd 625 Firmware, Qualcomm Sd 636 Firmware, Qualcomm Sd 665 Firmware, Qualcomm Sd 712 Firmware, Qualcomm Sd 710 Firmware, Qualcomm Sd 670 Firmware, Qualcomm Sd 730 Firmware, Qualcomm Sd 820a Firmware, Qualcomm Sd 835 Firmware, Qualcomm Sd 845 Firmware, Qualcomm Sd 850 Firmware, Qualcomm Sd 855 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm660 Firmware, Qualcomm Sdx24 Firmware.
No, Qualcomm Mdm9206 is not vulnerable to CVE-2019-10506.
No, Qualcomm Sd 670 devices are not vulnerable to CVE-2019-10506.
To fix CVE-2019-10506, apply the necessary security patches provided by Qualcomm.