CVE-2019-14055: Use After Free
Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8939, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS605, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SDX55, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14055?
The severity of CVE-2019-14055 is categorized as critical due to the potential for use-after-free and double-free conditions.
How do I fix CVE-2019-14055?
To fix CVE-2019-14055, update the affected Qualcomm firmware or Android operating system to the latest patched version.
What devices are affected by CVE-2019-14055?
CVE-2019-14055 affects a variety of Qualcomm devices, including those in the Snapdragon series and certain Android devices.
What are the potential exploit scenarios for CVE-2019-14055?
Exploitation of CVE-2019-14055 can lead to remote code execution and unauthorized access due to dangling pointer access.
How can I determine if my device is vulnerable to CVE-2019-14055?
You can determine if your device is vulnerable to CVE-2019-14055 by checking the firmware version against the security updates provided by Qualcomm and Android.