CVE-2019-2235: Buffer Overflow
Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, Qualcomm 215, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-2235?
CVE-2019-2235 is a vulnerability that occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic.
Which software are affected by CVE-2019-2235?
The vulnerability affects Qualcomm Mdm9206 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Mdm9655 Firmware, and Google Android.
What is the severity level of CVE-2019-2235?
The severity of CVE-2019-2235 is high with a CVSS score of 7.8.
How can I fix CVE-2019-2235?
To fix CVE-2019-2235, it is recommended to apply the patches and updates provided by Qualcomm and Google.
Where can I find more information about CVE-2019-2235?
More information about CVE-2019-2235 can be found on the Android Security Bulletin website and the Qualcomm Product Security Bulletins page.