CVE-2019-10520: Medium severity qualcomm qcs405 firmware vulnerability
An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 210/SD 212/SD 205, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-10520?
CVE-2019-10520 is a vulnerability that allows an unprivileged application to allocate GPU memory and exhaust all the memory, resulting in an out of memory condition in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 210/SD 212/SD 205, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850 / SD 855 devices.
What is the severity of CVE-2019-10520?
CVE-2019-10520 has a severity rating of 5.5 out of 10 (medium severity).
Which software is affected by CVE-2019-10520?
CVE-2019-10520 affects Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 210/SD 212/SD 205, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850 / SD 855 devices.
How can an unprivileged application exploit CVE-2019-10520?
An unprivileged application can exploit CVE-2019-10520 by calling memory allocation ioctl function to allocate GPU memory and exhaust all the memory on the affected devices.
Is Google Android vulnerable to CVE-2019-10520?
No, Google Android is not vulnerable to CVE-2019-10520.