First published: Mon Dec 02 2019(Updated: )
Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, APQ8064, APQ8096AU, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8939, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SDA660, SDM630, SDM636, SDM660, SDX20, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Apq8009 Firmware | ||
Qualcomm Apq8009 | ||
Qualcomm Apq8053 Firmware | ||
Qualcomm Apq8053 | ||
Google Android | ||
Qualcomm Apq8064 | ||
Qualcomm Apq8096au Firmware | ||
Qualcomm Apq8096au | ||
Qualcomm Ipq4019 Firmware | ||
Qualcomm Ipq4019 | ||
Qualcomm Ipq8064 Firmware | ||
Qualcomm Ipq8064 | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
Google Android | ||
Google Android | ||
Qualcomm Mdm9607 Firmware | ||
Qualcomm Mdm9607 | ||
Qualcomm Mdm9615 Firmware | ||
Qualcomm Mdm9615 | ||
Qualcomm Mdm9640 Firmware | ||
Qualcomm Mdm9640 | ||
Qualcomm Mdm9650 Firmware | ||
Qualcomm Mdm9650 | ||
Google Android | ||
Qualcomm Msm8909 | ||
Google Android | ||
Google Android | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Qca4531 Firmware | ||
Qualcomm Qca4531 | ||
Qualcomm Qca6174a Firmware | ||
Qualcomm Qca6174a | ||
Qualcomm Qca6574au Firmware | ||
Qualcomm Qca6574au | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Qca9558 Firmware | ||
Qualcomm Qca9558 | ||
Qualcomm Qca9880 Firmware | ||
Qualcomm Qca9880 | ||
Qualcomm Qca9886 Firmware | ||
Qualcomm Qca9886 | ||
Qualcomm Qca9980 Firmware | ||
Qualcomm Qca9980 | ||
Qualcomm Sda660 Firmware | ||
Qualcomm Sda660 | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Qualcomm Sdm636 Firmware | ||
Qualcomm Sdm636 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Qualcomm Sdx20 Firmware | ||
Qualcomm Sdx20 | ||
Qualcomm Sdx24 Firmware | ||
Google Android | ||
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10595 is a vulnerability that allows a possible buffer overwrite in the message handler due to the lack of validation of tid value calculated from packets received from firmware in various Qualcomm products.
The software affected by CVE-2019-10595 includes Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice, and various firmware versions of Qualcomm products such as apq8009, apq8053, apq8064, apq8096au, ipq4019, ipq8064, mdm9206, mdm9207c, mdm9607, mdm9615, mdm9640, mdm9650, msm8909, msm8939, msm8996au, qca4531, qca6174a, qca6574au, qca9377, qca9379, qca9558, qca9880, qca9886, qca9980, sda660, sdm630, sdm636, sdm660, sdx20, and sdx24.
The severity of CVE-2019-10595 is rated as high, with a severity value of 7.8.
To fix CVE-2019-10595, it is recommended to apply the necessary patches and updates provided by Qualcomm and Google. Refer to the references for more information on how to mitigate this vulnerability.
More information about CVE-2019-10595 can be found in the Qualcomm Product Security Bulletins and the Android Security Bulletin for December 2019.