CVE-2019-2276: Critical severity Google Android vulnerability
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2276?
CVE-2019-2276 has been classified as a high severity vulnerability due to potential out-of-bounds reads in affected devices.
How do I fix CVE-2019-2276?
To fix CVE-2019-2276, ensure that your device's firmware is updated to the latest version provided by Qualcomm that addresses this vulnerability.
What devices are affected by CVE-2019-2276?
CVE-2019-2276 affects multiple Qualcomm Snapdragon platforms, including mobile devices and automotive systems.
Can CVE-2019-2276 be exploited remotely?
Yes, CVE-2019-2276 could potentially be exploited remotely due to its nature of handling action frames from user-controlled spaces.
Is there a workaround for CVE-2019-2276 if I cannot update my firmware?
There are no specific workarounds for CVE-2019-2276; the best practice is to update the affected firmware to mitigate the vulnerability.