First published: Mon Jun 22 2020(Updated: )
Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, QCS405, Rennell, Saipan, SC8180X, SDX55, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9607 | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
qualcomm Rennell firmware | ||
qualcomm Rennell | ||
qualcomm Saipan firmware | ||
qualcomm Saipan | ||
qualcomm SC8180X firmware | ||
qualcomm SC8180X | ||
Qualcomm sdx55 firmware | ||
Qualcomm sdx55 | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
qualcomm SM8250 firmware | ||
Qualcomm SM8250 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14091 is classified as a high-severity vulnerability due to the potential for a double free condition leading to denial of service or memory corruption.
To remediate CVE-2019-14091, ensure that you update to the patched firmware versions provided by Qualcomm for affected devices.
CVE-2019-14091 affects various Qualcomm hardware including MDM9607, QCS405, Rennell, Saipan, SC8180X, SDX55, SM8150, SM8250, and SXR2130.
CVE-2019-14091 is associated with memory management vulnerabilities specifically related to a double free condition in the NPU.
Yes, the exploitation of CVE-2019-14091 could lead to potential system instability or malicious access if not addressed.