First published: Mon Mar 02 2020(Updated: )
Possible integer overflow while checking the length of frame which is a 32 bit integer and is added to another 32 bit integer which can lead to unexpected result during the check in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, MDM9607, MSM8998, QCA6584, QCN7605, QCS605, SDA660, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
qualcomm APQ8098 firmware | ||
qualcomm APQ8098 | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9607 | ||
qualcomm MSM8998 firmware | ||
Qualcomm MSM8998 | ||
qualcomm QCA6584 firmware | ||
qualcomm QCA6584 | ||
qualcomm qcn7605 Firmware | ||
qualcomm qcn7605 | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm SDA660 firmware | ||
qualcomm SDA660 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
qualcomm SDM636 firmware | ||
qualcomm SDM636 | ||
qualcomm SDM660 firmware | ||
qualcomm SDM660 | ||
qualcomm sdm670 firmware | ||
qualcomm sdm670 | ||
qualcomm sdm710 firmware | ||
qualcomm sdm710 | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
qualcomm sdm850 firmware | ||
qualcomm sdm850 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
Qualcomm SXR1130 Firmware | ||
Qualcomm SXR1130 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14086 is classified as a high severity vulnerability due to the potential for integer overflow.
Fixing CVE-2019-14086 involves updating the affected Qualcomm firmware to the latest patched version.
CVE-2019-14086 affects various Qualcomm products including Snapdragon platforms and certain firmware versions.
The risks associated with CVE-2019-14086 include potential denial of service or unauthorized access due to integer overflow.
Yes, CVE-2019-14086 has been publicly disclosed and is documented in security bulletins.