CVE-2019-10559: Null Pointer Dereference
Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8939, MSM8953, MSM8996, MSM8996AU, Nicobar, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10559?
CVE-2019-10559 is a vulnerability that allows accessing data buffer beyond the available data while parsing ogg clip, leading to null-pointer dereference and memory corruption.
Which software are affected by CVE-2019-10559?
CVE-2019-10559 affects Google Android, Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, and Snapdragon Vo.
What is the severity of CVE-2019-10559?
CVE-2019-10559 has a severity rating of 9.8 (critical).
How can I fix CVE-2019-10559?
To fix CVE-2019-10559, it is recommended to apply the patches and updates provided by Qualcomm and Google.
Where can I find more information about CVE-2019-10559?
You can find more information about CVE-2019-10559 on the Qualcomm Product Security Bulletins and the Android Security Bulletin websites.