CVE-2019-14031: Buffer Overflow
Buffer overflow can occur while parsing RSN IE containing list of PMK IDs which are more than the buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096, APQ8096AU, APQ8098, IPQ6018, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA8081, QCA9377, QCA9379, QCA9886, QCN7605, QCS405, QCS605, SA6155P, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14031?
CVE-2019-14031 is a vulnerability where a buffer overflow can occur while parsing RSN IE containing a list of PMK IDs which are more than the buffer size in Qualcomm Snapdragon devices.
What is the severity of CVE-2019-14031?
CVE-2019-14031 has a severity rating of 9.8 (Critical).
How can I mitigate CVE-2019-14031?
To mitigate CVE-2019-14031, users should apply the patches provided by Qualcomm and Google for the affected Snapdragon devices.