First published: Mon Dec 02 2019(Updated: )
Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, APQ8064, APQ8096AU, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8939, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SDA660, SDM630, SDM636, SDM660, SDX20, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm APQ8009W Firmware | ||
Qualcomm APQ8009 Firmware | ||
Qualcomm APQ8053 | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm APQ8064 AU Firmware | ||
Qualcomm APQ8064 AU Firmware | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm IPQ4019 | ||
Qualcomm IPQ4019 Firmware | ||
Qualcomm IPQ8064 Firmware | ||
Qualcomm IPQ8064 Firmware | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
qualcomm MDM9207C firmware | ||
Qualcomm 9207 LTE Modem | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9615M Firmware | ||
Qualcomm MDM9615 firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm 8909 Firmware | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8939 | ||
Qualcomm MSM8939 | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCA4531 | ||
Qualcomm QCA4531 | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm QCA9377 Firmware | ||
Qualcomm QCA9377 Firmware | ||
Qualcomm QCA9379 | ||
Qualcomm QCA9379 | ||
Qualcomm QCA9558 Firmware | ||
Qualcomm QCA9558 Firmware | ||
Qualcomm QCA9880 | ||
Qualcomm QCA9880 | ||
Qualcomm QCA9886 Firmware | ||
Qualcomm QCA9886 Firmware | ||
Qualcomm QCA9980 Firmware | ||
Qualcomm QCA9980 Firmware | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
Qualcomm SDM630 | ||
Qualcomm SDM630 Firmware | ||
Qualcomm SD 636 Firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10595 is a vulnerability that allows a possible buffer overwrite in the message handler due to the lack of validation of tid value calculated from packets received from firmware in various Qualcomm products.
The software affected by CVE-2019-10595 includes Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice, and various firmware versions of Qualcomm products such as apq8009, apq8053, apq8064, apq8096au, ipq4019, ipq8064, mdm9206, mdm9207c, mdm9607, mdm9615, mdm9640, mdm9650, msm8909, msm8939, msm8996au, qca4531, qca6174a, qca6574au, qca9377, qca9379, qca9558, qca9880, qca9886, qca9980, sda660, sdm630, sdm636, sdm660, sdx20, and sdx24.
The severity of CVE-2019-10595 is rated as high, with a severity value of 7.8.
To fix CVE-2019-10595, it is recommended to apply the necessary patches and updates provided by Qualcomm and Google. Refer to the references for more information on how to mitigate this vulnerability.
More information about CVE-2019-10595 can be found in the Qualcomm Product Security Bulletins and the Android Security Bulletin for December 2019.