First published: Mon Mar 02 2020(Updated: )
While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect length is specified in the attribute length field of extended SSI which can lead to integer underflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, APQ8096, APQ8098, IPQ6018, IPQ8074, MSM8996AU, MSM8998, Nicobar, QCA6174A, QCA6390, QCA6574AU, QCA8081, QCA9377, QCA9379, QCN7605, QCS404, QCS405, QCS605, Rennell, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm apq8009 firmware | ||
Qualcomm apq8009 | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm APQ8053 Firmware | ||
qualcomm APQ8096 firmware | ||
qualcomm APQ8096SG | ||
qualcomm APQ8098 firmware | ||
qualcomm APQ8098 | ||
qualcomm ipq6018 firmware | ||
qualcomm ipq6018 | ||
qualcomm ipq8074 firmware | ||
qualcomm IPQ8074 | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm MSM8996AU Firmware | ||
qualcomm MSM8998 firmware | ||
Qualcomm MSM8998 | ||
qualcomm Nicobar firmware | ||
qualcomm Nicobar | ||
Qualcomm qca6174a firmware | ||
Qualcomm qca6174a | ||
Qualcomm qca6390 firmware | ||
Qualcomm qca6390 | ||
qualcomm qca6574au firmware | ||
qualcomm qca6574au | ||
qualcomm QCA8081 firmware | ||
qualcomm QCA8081 | ||
Qualcomm qca9377 firmware | ||
Qualcomm qca9377 | ||
qualcomm qca9379 firmware | ||
qualcomm qca9379 | ||
qualcomm qcn7605 Firmware | ||
qualcomm qcn7605 | ||
qualcomm QCS404 firmware | ||
qualcomm QCS404 | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm Rennell firmware | ||
qualcomm Rennell | ||
qualcomm SC8180X firmware | ||
qualcomm SC8180X | ||
qualcomm SDA660 firmware | ||
qualcomm SDA660 | ||
qualcomm sda845 firmware | ||
qualcomm sda845 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
qualcomm SDM636 firmware | ||
qualcomm SDM636 | ||
qualcomm SDM660 firmware | ||
qualcomm SDM660 | ||
qualcomm sdm670 firmware | ||
qualcomm sdm670 | ||
qualcomm sdm710 firmware | ||
qualcomm sdm710 | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
qualcomm sdm850 firmware | ||
qualcomm sdm850 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
Qualcomm SXR1130 Firmware | ||
Qualcomm SXR1130 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-14083.
The severity of CVE-2019-14083 is critical.
Google Android and Qualcomm products are affected by CVE-2019-14083.
To fix CVE-2019-14083, it is recommended to apply the necessary security patches provided by Google or Qualcomm.
More information about CVE-2019-14083 can be found on the official Android Security Bulletin and Qualcomm Product Security Bulletins websites.