First published: Wed Nov 06 2019(Updated: )
Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, QCN7605, QCS405, QCS605, SDM845, SDX24, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm APQ8053 | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
qualcomm MDM9207C firmware | ||
Qualcomm 9207 LTE Modem | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm 8905 Firmware | ||
Qualcomm 8905 | ||
Qualcomm 8909 Firmware | ||
Qualcomm MSM8909W | ||
Qualcomm 8909 Firmware | ||
Qualcomm Snapdragon 8909 | ||
Qualcomm QCN7605 Firmware | ||
Qualcomm QCN7605 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SDA/SDM845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10565 is classified as a high severity vulnerability due to the potential for exploitation leading to a double free condition.
To mitigate CVE-2019-10565, update the affected Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2019-10565 affects various Qualcomm devices including APQ8053, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, and others.
CVE-2019-10565 is a double free vulnerability occurring in multi-threaded environments.
Exploitation of CVE-2019-10565 could lead to application crashes or arbitrary code execution due to memory corruption.