CVE-2019-10624: Buffer Overflow
While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int data type copied to u8 data type in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, MSM8996AU, QCA6574AU, QCN7605, Rennell, SC8180X, SDM710, SDX55, SM7150, SM8150, SM8250, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10624?
CVE-2019-10624 has a high severity due to its potential for buffer overflow exploitation.
How do I fix CVE-2019-10624?
To fix CVE-2019-10624, apply the latest firmware update from Qualcomm that addresses this vulnerability.
Which devices are affected by CVE-2019-10624?
CVE-2019-10624 affects multiple Qualcomm chipsets including APQ8096AU, MSM8996AU, QCA6574AU, and others.
What type of issue does CVE-2019-10624 describe?
CVE-2019-10624 describes an integer truncation issue leading to a possible buffer overflow.
Can CVE-2019-10624 lead to remote code execution?
Yes, CVE-2019-10624 may allow attackers to execute arbitrary code remotely due to the buffer overflow.