CVE-2019-14101: Input Validation
Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than expected length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCN7605, QCS404, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14101?
CVE-2019-14101 has a medium severity level due to the potential for out of bounds read vulnerabilities.
How do I fix CVE-2019-14101?
To fix CVE-2019-14101, ensure that you apply the security patches provided by Qualcomm for the affected firmware versions.
What products are affected by CVE-2019-14101?
CVE-2019-14101 affects various Qualcomm firmware including but not limited to APQ8009, APQ8096, and MDM9205.
Can I exploit CVE-2019-14101 remotely?
Yes, the out of bounds read vulnerability outlined in CVE-2019-14101 can potentially be exploited remotely.
What is the nature of the vulnerability in CVE-2019-14101?
CVE-2019-14101 is an out of bounds read vulnerability that occurs when the user-provided input length is less than the expected length.