First published: Mon Sep 30 2019(Updated: )
Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855, SDM439, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
Qualcomm Qualcomm 215 Firmware | ||
Qualcomm Qualcomm 215 | ||
qualcomm SD 425 firmware | ||
qualcomm SD 425 | ||
Qualcomm SD 439 firmware | ||
Qualcomm SD 439 | ||
Qualcomm SD 429 firmware | ||
Qualcomm SD 429 | ||
Qualcomm SD 450 firmware | ||
Qualcomm SD 450 | ||
qualcomm SD 625 firmware | ||
qualcomm SD 625 | ||
Qualcomm SD 632 firmware | ||
Qualcomm SD 632 | ||
Qualcomm SD 665 Firmware | ||
qualcomm SD 665 | ||
qualcomm SD 675 firmware | ||
qualcomm SD 675 | ||
qualcomm SD 712 firmware | ||
qualcomm SD 712 | ||
qualcomm SD 710 firmware | ||
qualcomm SD 710 | ||
qualcomm SD 670 firmware | ||
qualcomm SD 670 | ||
qualcomm SD 730 firmware | ||
qualcomm SD 730 | ||
qualcomm SD 845 firmware | ||
qualcomm SD 845 | ||
qualcomm SD 850 firmware | ||
qualcomm SD 850 | ||
qualcomm SD 855 firmware | ||
qualcomm SD 855 | ||
qualcomm SDM439 firmware | ||
qualcomm SDM439 | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 |
https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2284 is a vulnerability related to a possible use-after-free issue due to a race condition while calling camera ioctl concurrently in multiple Qualcomm Snapdragon devices.
CVE-2019-2284 affects multiple Qualcomm Snapdragon devices including MSM8909W, QCS405, QCS605, Qualcomm 215, SD 425, SD 439, and more.
CVE-2019-2284 has a severity value of 7, indicating a high severity level.
To fix CVE-2019-2284, it is recommended to apply the necessary patches and updates provided by Qualcomm or the respective device manufacturers.
More information about CVE-2019-2284 can be found in the Code Aurora security bulletin for August 2019.