CVE-2019-13994: Integer Overflow
u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than the actual packet size can lead to memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13994?
CVE-2019-13994 has a severity rating that can lead to memory corruption and potential information leakage.
How do I fix CVE-2019-13994?
To fix CVE-2019-13994, ensure that updates from Qualcomm or your device manufacturer are applied as they address this vulnerability.
What devices are affected by CVE-2019-13994?
CVE-2019-13994 affects various Qualcomm Snapdragon components, including Android devices that utilize affected firmware versions.
What type of vulnerability is CVE-2019-13994?
CVE-2019-13994 is classified as a memory corruption vulnerability resulting from inadequate validation of data fragment sizes.
When was CVE-2019-13994 disclosed?
CVE-2019-13994 was disclosed in August 2020 as part of Qualcomm's security bulletins.