CVE-2019-10561: Medium severity qualcomm apq8009w firmware vulnerability
Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, MDM9206, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10561?
CVE-2019-10561 is a vulnerability that can cause an invalid pointer dereference and lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking.
How severe is the CVE-2019-10561 vulnerability?
The CVE-2019-10561 vulnerability has a severity rating of 5.5 out of 10 (medium).
Which software are affected by CVE-2019-10561?
CVE-2019-10561 affects Google Android, Qualcomm APQ8009 Firmware, Qualcomm APQ8017 Firmware, Qualcomm APQ8053 Firmware, Qualcomm APQ8096 Firmware, Qualcomm APQ8096au Firmware, Qualcomm APQ8098 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9607 Firmware, Qualcomm Msm8905 Firmware, Qualcomm Msm8909 Firmware, Qualcomm Msm8909w Firmware, Qualcomm Msm8917 Firmware, Qualcomm Msm8920 Firmware, Qualcomm Msm8937 Firmware, Qualcomm Msm8940 Firmware, Qualcomm Msm8953 Firmware, Qualcomm Msm8996 Firmware, Qualcomm Msm8996au Firmware, Qualcomm MSM8998 Firmware, Qualcomm Qm215 Firmware, Qualcomm Sda660 Firmware, Qualcomm Sdm429 Firmware, Qualcomm Sdm439 Firmware, Qualcomm Sdm450 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm632 Firmware, Qualcomm Sdm636 Firmware, and Qualcomm Sdm660 Firmware.
How can I fix CVE-2019-10561 vulnerability?
To fix the CVE-2019-10561 vulnerability, it is recommended to apply the patches provided by Qualcomm. Please refer to the official Qualcomm product security bulletin for more information.
Where can I find more information about CVE-2019-10561?
More information about CVE-2019-10561 can be found in the official Qualcomm product security bulletin: https://www.qualcomm.com/company/product-security/bulletins/january-2020-bulletin