First published: Mon Apr 06 2020(Updated: )
Out of bound write can occur in radio measurement request if STA receives multiple invalid rrm measurement request from AP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8096AU, MSM8998, Nicobar, QCA6574AU, QCS605, Rennell, SA6155P, Saipan, SC8180X, SDM660, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm APQ8053 Firmware | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm apq8096au firmware | ||
Qualcomm apq8096au | ||
qualcomm MSM8998 firmware | ||
Qualcomm MSM8998 | ||
qualcomm Nicobar firmware | ||
qualcomm Nicobar | ||
qualcomm qca6574au firmware | ||
qualcomm qca6574au | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm Rennell firmware | ||
qualcomm Rennell | ||
Qualcomm Sa6155p Firmware | ||
qualcomm SA6155P | ||
qualcomm Saipan firmware | ||
qualcomm Saipan | ||
qualcomm SC8180X firmware | ||
qualcomm SC8180X | ||
qualcomm SDM660 firmware | ||
qualcomm SDM660 | ||
qualcomm sdm710 firmware | ||
qualcomm sdm710 | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 | ||
Qualcomm sdx55 firmware | ||
Qualcomm sdx55 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
qualcomm SM8250 firmware | ||
Qualcomm SM8250 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14131 has a severity rating that indicates it may lead to out-of-bounds writes, impacting system reliability.
To fix CVE-2019-14131, ensure that you update the affected firmware or software to the latest version provided by Qualcomm or your device manufacturer.
CVE-2019-14131 affects multiple Qualcomm chipsets, including APQ8053, APQ8096AU, and MSM8998 among others.
CVE-2019-14131 is classified as an out-of-bounds write vulnerability.
CVE-2019-14131 could potentially be exploited remotely if an attacker can send multiple invalid requests to a vulnerable access point.