CVE-2019-10558: High severity Google Android vulnerability
While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be controlled by DSP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SDX55, SM6150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10558?
The severity of CVE-2019-10558 is considered high due to the potential for exploitation that could lead to unauthorized access.
What causes CVE-2019-10558?
CVE-2019-10558 is caused by an out of bounds write vulnerability in the FastRPC HLOS driver due to a data buffer controlled by the DSP.
How can I mitigate CVE-2019-10558?
To mitigate CVE-2019-10558, ensure that devices are updated with the latest firmware provided by Qualcomm.
Which devices are affected by CVE-2019-10558?
CVE-2019-10558 affects various Qualcomm-based devices including Snapdragon models across automotive, consumer electronics, and mobile sectors.
How do I check if my device is vulnerable to CVE-2019-10558?
To check if your device is vulnerable to CVE-2019-10558, verify the firmware version against the security bulletins released by Qualcomm.