First published: Tue Jun 02 2020(Updated: )
Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, QCS605, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM670, SDM710, SDM845, SDX20, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm APQ8053 | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm 8098 Firmware | ||
Qualcomm APQ8098 | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
qualcomm MDM9207C firmware | ||
Qualcomm 9207 LTE Modem | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm 8905 Firmware | ||
Qualcomm 8905 | ||
Qualcomm 8909 Firmware | ||
Qualcomm Snapdragon 8909 | ||
Qualcomm MSM8917 | ||
Qualcomm MSM8917 Firmware | ||
Qualcomm 8953Pro Firmware | ||
Qualcomm MSM8953 Firmware | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
Qualcomm SD 845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SDM429W | ||
Qualcomm SD429 | ||
Qualcomm SDM429W | ||
qualcomm SDM429W firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SD 670 Firmware | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SD 710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDA/SDM845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14039 is a vulnerability caused by an out-of-bound read in the adm callback function due to incorrect boundary checks for payload in command response in multiple Qualcomm products.
CVE-2019-14039 affects Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables in various models.
CVE-2019-14039 has a severity score of 7.1 (high).
CVE-2019-14039 occurs due to incorrect boundary checks for payload in command response, leading to an out-of-bound read in the adm callback function.
For information on fixes and mitigations for CVE-2019-14039, refer to the official Qualcomm product security bulletin.