CVE-2019-14000: High severity Google Android vulnerability
Lack of check that the RX FIFO write index that is read from shared RAM is less than the FIFO size results into memory corruption and potential information leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ6018, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCS404, QCS405, QCS605, QM215, Rennell, SA6155P, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14000?
CVE-2019-14000 has a high severity rating due to the potential for memory corruption and information leakage.
How do I fix CVE-2019-14000?
To mitigate CVE-2019-14000, ensure that you update your Qualcomm hardware firmware to the latest version provided by Qualcomm.
What devices are affected by CVE-2019-14000?
CVE-2019-14000 affects various Qualcomm Snapdragon-based devices across different categories, including automotive, mobile, and IoT.
Can CVE-2019-14000 be exploited remotely?
Yes, CVE-2019-14000 can be exploited remotely, potentially allowing an attacker to gain unauthorized access to sensitive information.
Is there a specific patch for CVE-2019-14000?
Yes, Qualcomm has released firmware updates that specifically address and patch the vulnerabilities associated with CVE-2019-14000.