CVE-2019-2259: Critical severity android vulnerability
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-2259?
CVE-2019-2259 is a vulnerability that occurs due to a resource allocation error while playing a video with dimensions that are larger than the supported dimension.
What software products are affected by CVE-2019-2259?
Google Android, Qualcomm MSM8909w Firmware, Qualcomm MSM8996au Firmware, Qualcomm Qcs605 Firmware, Qualcomm Qm215 Firmware, Qualcomm Sd 210 Firmware, Qualcomm Sd 212 Firmware, Qualcomm Sd 205 Firmware, Qualcomm Sd 425 Firmware, Google Android, Qualcomm Sd 430 Firmware, Google Android, Qualcomm Sd 439 Firmware, Qualcomm Sd 429 Firmware, Qualcomm Sd 450 Firmware, Qualcomm Sd 625 Firmware, Qualcomm Sd 632 Firmware, Qualcomm Sd 636 Firmware, Google Android, Qualcomm Sd 670 Firmware, Qualcomm Sd 730 Firmware, Google Android, Qualcomm Sd 820a Firmware, Qualcomm Sd 835 Firmware, Qualcomm Sd 845 Firmware, Qualcomm Sd 850 Firmware, Qualcomm Sd 855 Firmware, Google Android, Qualcomm Sd 8cx Firmware, Google Android, Qualcomm Sdm439 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm660 Firmware, Google Android, Qualcomm Snapdragon High Med 2016 Firmware, Qualcomm Sxr1130 Firmware are all affected by CVE-2019-2259.
What is the severity of CVE-2019-2259?
CVE-2019-2259 has a severity rating of 9.8 (Critical).
How can I fix CVE-2019-2259?
To fix CVE-2019-2259, it is recommended to update to the latest version of the affected software or apply the patches provided by the vendor.
Where can I find more information about CVE-2019-2259?
You can find more information about CVE-2019-2259 on the official Android Security Bulletin for May 2019 and the Qualcomm Product Security Bulletins.