CVE-2019-13995: Integer Overflow
u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13995?
CVE-2019-13995 is classified as a high severity vulnerability due to potential memory corruption and information leakage risks.
How do I fix CVE-2019-13995?
To fix CVE-2019-13995, update the affected Qualcomm firmware to the latest version provided by the vendor.
Which devices are affected by CVE-2019-13995?
CVE-2019-13995 affects various Qualcomm platforms including Snapdragon Auto, Compute, Connectivity, and Consumer Electronics.
What type of vulnerability is CVE-2019-13995?
CVE-2019-13995 is an integer overflow vulnerability found in the handling of fragment sizes in shared memory.
Can CVE-2019-13995 be exploited remotely?
Exploitation of CVE-2019-13995 could potentially be conducted remotely, depending on the application context and device configurations.