CVE-2019-2260: Use After Free
A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDM630, SDM660, SDX20, SDX24, SnapdragonHighMed2016, SXR1130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2260?
CVE-2019-2260 is considered to have a high severity due to the potential for a use after free condition.
How do I fix CVE-2019-2260?
To fix CVE-2019-2260, apply the latest firmware updates provided by Qualcomm for the affected Snapdragon products.
Which devices are affected by CVE-2019-2260?
CVE-2019-2260 affects various Snapdragon devices, including Snapdragon Auto, Compute, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables.
What is a race condition in the context of CVE-2019-2260?
In the context of CVE-2019-2260, a race condition refers to a flaw that allows multiple processes to access shared resources simultaneously, potentially leading to unpredictable behaviors.
Is there a workaround for CVE-2019-2260?
There are no recommended workarounds for CVE-2019-2260; the best course of action is to update to the patched firmware.