First published: Mon Aug 05 2019(Updated: )
BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS405, QCS605, SD 636, SD 675, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Qcs405 Firmware | ||
Qualcomm Qcs405 | ||
Qualcomm Qcs605 Firmware | ||
Google Android | ||
Qualcomm Sd 636 Firmware | ||
Qualcomm Sd 636 | ||
Google Android | ||
Qualcomm Sd 675 | ||
Qualcomm Sd 730 Firmware | ||
Qualcomm Sd 730 | ||
Qualcomm Sd 820a Firmware | ||
Qualcomm Sd 820a | ||
Qualcomm Sd 835 Firmware | ||
Qualcomm Sd 835 | ||
Qualcomm Sd 845 Firmware | ||
Qualcomm Sd 845 | ||
Qualcomm Sd 850 Firmware | ||
Qualcomm Sd 850 | ||
Qualcomm Sd 855 Firmware | ||
Qualcomm Sd 855 | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Google Android |
https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10510 is a vulnerability that can cause the BT process to crash and BT to toggle due to a null pointer dereference when an invalid vendor pass through command is sent from a remote device.
CVE-2019-10510 affects Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS405, QCS605, SD 636, SD 675, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM63.
The severity of CVE-2019-10510 is high, with a CVSS score of 8.2.
To fix CVE-2019-10510, update your software to the latest version provided by Qualcomm or the respective vendor.
Yes, you can find more information about CVE-2019-10510 in the references provided: [Link to Source Code Aurora](https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/system/bt/commit/?id=d005a97b4daa188a15696c46c72b67e5f49f7fc6), [Link to Android Security Bulletin](https://source.android.com/docs/security/bulletin/2019-08-01), [Link to Code Aurora Security Bulletin](https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin).