CVE-2019-10597: Input Validation
kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, MSM8996, MSM8996AU, Nicobar, QCS605, Rennell, Saipan, SC7180, SC8180X, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10597?
CVE-2019-10597 is a vulnerability in the kernel of certain Qualcomm Snapdragon devices that allows arbitrary memory write.
Which devices are affected by CVE-2019-10597?
CVE-2019-10597 affects Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, MSM8996, MSM8996AU, Nicobar, QCS605, Rennell, Saipan, SC7180, SC8180x, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130, and SXR2130.
What is the severity of CVE-2019-10597?
CVE-2019-10597 has a severity rating of 7.8 (high).
How can I fix CVE-2019-10597?
To fix CVE-2019-10597, it is recommended to apply the security patches provided by Qualcomm and Google for the affected devices.
Where can I find more information about CVE-2019-10597?
You can find more information about CVE-2019-10597 on the Qualcomm Product Security Bulletin and Android Security Bulletin for June 2020.