CVE-2019-14072: Use After Free
Unhandled paging request is observed due to dereferencing an already freed object because of race condition between sparse free and sparse bind ioctls which access the same physical entry in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8096AU, APQ8098, MDM9607, MSM8909W, MSM8939, MSM8953, MSM8996AU, Nicobar, QCS405, QCS605, Rennell, SA6155P, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM450, SDM632, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14072?
CVE-2019-14072 has been classified with a medium severity rating, indicating potential risks to system stability and security.
How do I fix CVE-2019-14072?
To mitigate CVE-2019-14072, update your affected Qualcomm firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2019-14072?
CVE-2019-14072 affects multiple Qualcomm Snapdragon platforms, including Snapdragon Auto and Snapdragon Consumer IoT among others.
What kind of issue is CVE-2019-14072 associated with?
CVE-2019-14072 is associated with an unhandled paging request resulting from a race condition due to concurrent access to freed memory.
Is CVE-2019-14072 being actively exploited?
There are currently no public reports indicating that CVE-2019-14072 is being actively exploited in the wild.