CVE-2019-14114: Buffer Overflow
Buffer overflow in WLAN firmware while parsing GTK IE containing GTK key having length more than the buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, IPQ6018, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8996AU, MSM8998, Nicobar, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA8081, QCA9377, QCA9379, QCA9886, QCN7605, QCS404, QCS405, QCS605, Rennell, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14114?
CVE-2019-14114 has a high severity rating due to the potential for buffer overflow exploitation in WLAN firmware.
How do I fix CVE-2019-14114?
To fix CVE-2019-14114, vendors should apply the latest firmware updates that address the buffer overflow vulnerability.
Which systems are affected by CVE-2019-14114?
CVE-2019-14114 affects various Qualcomm firmware systems, including Snapdragon platforms and Android devices.
What kind of attack can exploit CVE-2019-14114?
An attacker can exploit CVE-2019-14114 to cause buffer overflow, which may lead to arbitrary code execution or denial of service.
Is there a workaround for CVE-2019-14114?
There is no documented workaround for CVE-2019-14114; the recommended action is to update to secure firmware versions.