CVE-2019-10602: Use After Free
Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCS605, SDA660, SDM845, SDX20, SM8150
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the main implications of CVE-2019-10602?
CVE-2019-10602 could lead to a potential use-after-free heap error which may allow attackers to execute arbitrary code.
Which Qualcomm products are affected by CVE-2019-10602?
CVE-2019-10602 affects several Qualcomm products, including Snapdragon Auto, Snapdragon Compute, and various Snapdragon models.
How can I mitigate the risks associated with CVE-2019-10602?
To mitigate CVE-2019-10602, users should update their firmware to versions that have addressed this vulnerability.
Is CVE-2019-10602 exploited in the wild?
At the time of reporting, there is no public information confirming that CVE-2019-10602 is being actively exploited in the wild.
What kind of error does CVE-2019-10602 involve?
CVE-2019-10602 involves a use-after-free heap error during Validate/Present calls in display hardware composers.