First published: Mon Apr 01 2019(Updated: )
Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCS605, SD 675, SD 712 / SD 710 / SD 670, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SM7150, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm SD 675 firmware | ||
qualcomm SD 675 | ||
qualcomm SD 712 firmware | ||
qualcomm SD 712 | ||
qualcomm SD 710 firmware | ||
qualcomm SD 710 | ||
qualcomm SD 670 firmware | ||
qualcomm SD 670 | ||
qualcomm SD 835 firmware | ||
qualcomm SD 835 | ||
qualcomm SD 845 firmware | ||
qualcomm SD 845 | ||
qualcomm SD 850 firmware | ||
qualcomm SD 850 | ||
qualcomm SD 855 firmware | ||
qualcomm SD 855 | ||
qualcomm SD 8CX firmware | ||
qualcomm SD 8CX | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
Qualcomm SXR1130 firmware | ||
Qualcomm SXR1130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2250 has a high severity rating due to the potential for arbitrary memory writes impacting system stability and security.
To fix CVE-2019-2250, apply the latest firmware updates from Qualcomm or your device manufacturer that address this vulnerability.
CVE-2019-2250 affects various Qualcomm Snapdragon processors, including QCS605, SD 675, SD 712, SD 710, SD 670, SD 835, SD 845, SD 850, SD 855, SD 8CX, SM7150, and SXR1130.
The potential impacts of CVE-2019-2250 include denial of service and exploitation risks, as the kernel may be manipulated to write to unintended memory locations.
There are currently no known workarounds for CVE-2019-2250, so applying the appropriate firmware patch is necessary to mitigate the vulnerability.