CVE-2019-14039: High severity qualcomm apq8053 vulnerability
Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, QCS605, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM670, SDM710, SDM845, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14039?
CVE-2019-14039 is a vulnerability caused by an out-of-bound read in the adm callback function due to incorrect boundary checks for payload in command response in multiple Qualcomm products.
Which Qualcomm products are affected by CVE-2019-14039?
CVE-2019-14039 affects Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables in various models.
What is the severity of CVE-2019-14039?
CVE-2019-14039 has a severity score of 7.1 (high).
How does CVE-2019-14039 occur?
CVE-2019-14039 occurs due to incorrect boundary checks for payload in command response, leading to an out-of-bound read in the adm callback function.
Is there a fix available for CVE-2019-14039?
For information on fixes and mitigations for CVE-2019-14039, refer to the official Qualcomm product security bulletin.