First published: Mon May 06 2019(Updated: )
An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm ZZ QCS605 firmware | ||
Qualcomm QCS605 Firmware | ||
Qualcomm 215 Firmware | ||
Qualcomm 215 | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SDR425 Firmware | ||
Qualcomm Snapdragon 425 | ||
Qualcomm SD427 Firmware | ||
Qualcomm SD 427 firmware | ||
Qualcomm SD 430 Firmware | ||
Qualcomm SD 430 Firmware | ||
qualcomm sd435 firmware | ||
Qualcomm Snapdragon 435 | ||
Qualcomm SD 439 | ||
Qualcomm SD 439 firmware | ||
Qualcomm SD429 Firmware | ||
Qualcomm SD 429 Firmware | ||
Qualcomm SDM450 Firmware | ||
Qualcomm SDM450 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD632 Firmware | ||
Qualcomm SD 632 firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm Snapdragon 636 | ||
Qualcomm SD 675 Firmware | ||
Qualcomm Snapdragon 675 | ||
Qualcomm Snapdragon 712 Firmware | ||
Qualcomm Snapdragon 712 | ||
qualcomm sdm710 firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SDM670 | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SD855 Firmware | ||
Qualcomm SD855 Firmware | ||
Qualcomm SD 8cx firmware | ||
Qualcomm Snapdragon 8cx | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
qualcomm SDM439 firmware | ||
Qualcomm SDM439 Firmware | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm Snapdragon High Med 2016 | ||
Qualcomm Snapdragon High Med 2016 Firmware | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2256 is a vulnerability that allows an unprivileged user to craft a bitstream that can execute code in certain Qualcomm products.
CVE-2019-2256 affects Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Google Android, Qualcomm Mdm9650 Firmware, and Qualcomm Qcs605 Firmware.
CVE-2019-2256 is considered a critical vulnerability with a severity value of 9.
An unprivileged user can exploit CVE-2019-2256 by crafting a bitstream with a payload that gains code execution in the affected Qualcomm products.
You can find more information about CVE-2019-2256 in the official security bulletins from Google Android and Qualcomm.