First published: Mon Mar 02 2020(Updated: )
UTCB object has a function pointer called by the reaper to deallocate its memory resources and this address can potentially be corrupted by stack overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, MDM9650, QCS605, SA6155P, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm 9205 Firmware | ||
Qualcomm 9205 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MDM9650 | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
Qualcomm Sa6155p Firmware | ||
qualcomm SA6155P | ||
qualcomm SC8180X firmware | ||
qualcomm SC8180X | ||
qualcomm sda845 firmware | ||
qualcomm sda845 | ||
qualcomm sdm670 firmware | ||
qualcomm sdm670 | ||
qualcomm sdm710 firmware | ||
qualcomm sdm710 | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
qualcomm sdm850 firmware | ||
qualcomm sdm850 | ||
Qualcomm sdx55 firmware | ||
Qualcomm sdx55 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
qualcomm SM8250 firmware | ||
Qualcomm SM8250 | ||
Qualcomm SXR1130 Firmware | ||
Qualcomm SXR1130 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10612 is classified as a high-severity vulnerability due to the potential for memory corruption from a stack overflow.
To mitigate CVE-2019-10612, ensure you update any affected Qualcomm firmware to the latest version provided by the manufacturer.
CVE-2019-10612 affects several Qualcomm platforms, including Snapdragon Auto and Snapdragon Mobile variants.
Exploitation of CVE-2019-10612 could lead to a denial of service or arbitrary code execution due to corrupted memory.
Users of devices powered by affected Qualcomm chipsets may be at risk from CVE-2019-10612 if they are using unpatched firmware.