First published: Mon Sep 30 2019(Updated: )
Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855, SDM439, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm ZZ QCS605 firmware | ||
Qualcomm QCS605 Firmware | ||
Qualcomm 215 Mobile Firmware | ||
Qualcomm 215 Firmware | ||
Qualcomm SDR425 Firmware | ||
Qualcomm Snapdragon 425 | ||
Qualcomm SD 439 | ||
Qualcomm SD 439 firmware | ||
Qualcomm SD429 Firmware | ||
Qualcomm SD 429 Firmware | ||
Qualcomm SDM450 Firmware | ||
Qualcomm SDM450 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD632 Firmware | ||
Qualcomm SD 632 firmware | ||
Qualcomm Snapdragon 665 | ||
Qualcomm Snapdragon 665 | ||
Qualcomm SD 675 Firmware | ||
Qualcomm Snapdragon 675 | ||
Qualcomm Snapdragon 712 Firmware | ||
Qualcomm Snapdragon 712 | ||
qualcomm sdm710 firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SDM670 | ||
Qualcomm SD 730 Firmware | ||
Qualcomm Snapdragon 730 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SD855 Firmware | ||
Qualcomm SD855 Firmware | ||
qualcomm SDM439 firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 |
https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2284 is a vulnerability related to a possible use-after-free issue due to a race condition while calling camera ioctl concurrently in multiple Qualcomm Snapdragon devices.
CVE-2019-2284 affects multiple Qualcomm Snapdragon devices including MSM8909W, QCS405, QCS605, Qualcomm 215, SD 425, SD 439, and more.
CVE-2019-2284 has a severity value of 7, indicating a high severity level.
To fix CVE-2019-2284, it is recommended to apply the necessary patches and updates provided by Qualcomm or the respective device manufacturers.
More information about CVE-2019-2284 can be found in the Code Aurora security bulletin for August 2019.