First published: Thu Nov 21 2019(Updated: )
Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MSM8909, MSM8909W, Nicobar, QCA9980, QCS405, QCS605, SDM845, SDX24, SM7150, SM8150
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm APQ8053 Firmware | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm IPQ4019 | ||
Qualcomm IPQ4019 Firmware | ||
Qualcomm IPQ8064 | ||
qualcomm IPQ8064 firmware | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MDM9206 | ||
qualcomm MDM9207C firmware | ||
qualcomm MDM9207C | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9607 | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
qualcomm Nicobar firmware | ||
qualcomm Nicobar | ||
qualcomm qca9980 firmware | ||
qualcomm qca9980 | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2266 is classified as a high severity vulnerability due to the potential for a double free issue in the kernel.
To fix CVE-2019-2266, ensure that you apply the firmware updates provided by Qualcomm for the affected Snapdragon products.
CVE-2019-2266 affects various Qualcomm Snapdragon devices across mobile, IoT, and automotive sectors.
CVE-2019-2266 involves a possible double free vulnerability that can affect the handling of camera sensor and power sequence.
As of now, there are no publicly known exploits specifically targeting CVE-2019-2266.