CVE-2019-10616: Null Pointer Dereference
Possibility of null pointer access if the SPDM commands are executed in the non-standard way in TZ. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8016, MDM9150, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8998, SA6155P, SDX24
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10616?
CVE-2019-10616 is a vulnerability that allows null pointer access if the SPDM commands are executed in a non-standard way in certain Qualcomm products running Google Android.
Which products are affected by CVE-2019-10616?
CVE-2019-10616 affects Google Android on Qualcomm products such as Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile.
How severe is CVE-2019-10616?
CVE-2019-10616 has a severity rating of 5.5 (high).
How can I mitigate the CVE-2019-10616 vulnerability?
To mitigate the CVE-2019-10616 vulnerability, it is recommended to apply the security updates provided by Google and Qualcomm.
Where can I find more information about CVE-2019-10616?
More information about CVE-2019-10616 can be found in the Android Security Bulletin for March 2020 and the Qualcomm Product Security Bulletins.