CVE-2019-10595: Input Validation
Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, APQ8064, APQ8096AU, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8939, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SDA660, SDM630, SDM636, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-10595?
CVE-2019-10595 is a vulnerability that allows a possible buffer overwrite in the message handler due to the lack of validation of tid value calculated from packets received from firmware in various Qualcomm products.
Which software is affected by CVE-2019-10595?
The software affected by CVE-2019-10595 includes Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice, and various firmware versions of Qualcomm products such as apq8009, apq8053, apq8064, apq8096au, ipq4019, ipq8064, mdm9206, mdm9207c, mdm9607, mdm9615, mdm9640, mdm9650, msm8909, msm8939, msm8996au, qca4531, qca6174a, qca6574au, qca9377, qca9379, qca9558, qca9880, qca9886, qca9980, sda660, sdm630, sdm636, sdm660, sdx20, and sdx24.
What is the severity of CVE-2019-10595?
The severity of CVE-2019-10595 is rated as high, with a severity value of 7.8.
How can I fix CVE-2019-10595?
To fix CVE-2019-10595, it is recommended to apply the necessary patches and updates provided by Qualcomm and Google. Refer to the references for more information on how to mitigate this vulnerability.
Where can I find more information about CVE-2019-10595?
More information about CVE-2019-10595 can be found in the Qualcomm Product Security Bulletins and the Android Security Bulletin for December 2019.