CVE-2019-10509: Use After Free
Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCA6574AU, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-10509?
CVE-2019-10509 is a vulnerability that allows an attacker to execute arbitrary code or cause a denial of service.
What is the severity of CVE-2019-10509?
CVE-2019-10509 has a severity rating of 9.8 (Critical).
Which devices are affected by CVE-2019-10509?
Devices such as Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables in MSM8909W, MSM8996AU, QCA6574AU, QCS40 are affected.
How can an attacker exploit CVE-2019-10509?
An attacker can exploit CVE-2019-10509 by sending specially crafted packets to the vulnerable device.
Is there a fix for CVE-2019-10509?
Yes, please refer to the official references for patch information and updates.