First published: Mon Jul 01 2019(Updated: )
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9607 | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm qca6174a firmware | ||
Qualcomm qca6174a | ||
qualcomm qca6574au firmware | ||
qualcomm qca6574au | ||
Qualcomm qca9377 firmware | ||
Qualcomm qca9377 | ||
qualcomm qca9379 firmware | ||
qualcomm qca9379 | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm SD 636 firmware | ||
qualcomm SD 636 | ||
Qualcomm SD 665 Firmware | ||
qualcomm SD 665 | ||
qualcomm SD 675 firmware | ||
qualcomm SD 675 | ||
qualcomm SD 712 firmware | ||
qualcomm SD 712 | ||
qualcomm SD 710 firmware | ||
qualcomm SD 710 | ||
qualcomm SD 670 firmware | ||
qualcomm SD 670 | ||
qualcomm SD 730 firmware | ||
qualcomm SD 730 | ||
qualcomm SD 820A firmware | ||
qualcomm SD 820A | ||
qualcomm SD 845 firmware | ||
qualcomm SD 845 | ||
qualcomm SD 850 firmware | ||
qualcomm SD 850 | ||
qualcomm SD 855 firmware | ||
qualcomm SD 855 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
qualcomm SDM660 firmware | ||
qualcomm SDM660 | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 | ||
Android |
https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2276 has been classified as a high severity vulnerability due to potential out-of-bounds reads in affected devices.
To fix CVE-2019-2276, ensure that your device's firmware is updated to the latest version provided by Qualcomm that addresses this vulnerability.
CVE-2019-2276 affects multiple Qualcomm Snapdragon platforms, including mobile devices and automotive systems.
Yes, CVE-2019-2276 could potentially be exploited remotely due to its nature of handling action frames from user-controlled spaces.
There are no specific workarounds for CVE-2019-2276; the best practice is to update the affected firmware to mitigate the vulnerability.