CVE-2019-10544: Buffer Overflow
Improper length check on source buffer to handle userspace data received can lead to out-of-bound access in diag handlers in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996AU, MSM8998, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10544?
CVE-2019-10544 has a severity rating of high due to potential out-of-bounds access.
How do I fix CVE-2019-10544?
To fix CVE-2019-10544, apply the firmware updates provided by Qualcomm for the affected devices.
Which devices are affected by CVE-2019-10544?
CVE-2019-10544 affects several Qualcomm Snapdragon firmware versions across a variety of devices including mobile and IoT platforms.
Can CVE-2019-10544 be exploited remotely?
Yes, CVE-2019-10544 could potentially be exploited remotely if the vulnerable firmware is used in networked environments.
Is there a permanent solution to CVE-2019-10544?
The permanent solution to CVE-2019-10544 is to ensure that all affected devices are updated to the latest firmware version issued by Qualcomm.