CVE-2019-2288: High severity android vulnerability
Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8976, MSM8996, MSM8996AU, MSM8998, QCA8081, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2288?
CVE-2019-2288 has been rated as a high severity vulnerability due to the potential for out of bounds write exploitation.
How do I fix CVE-2019-2288?
To fix CVE-2019-2288, you should update the affected Qualcomm firmware based on the manufacturer's security bulletin.
Which devices are affected by CVE-2019-2288?
CVE-2019-2288 affects various Qualcomm platforms including Snapdragon Auto, Snapdragon Compute, and several others.
What type of vulnerability is CVE-2019-2288?
CVE-2019-2288 is classified as an out of bounds write vulnerability.
What are the potential impacts of CVE-2019-2288?
Exploitation of CVE-2019-2288 could allow an attacker to execute arbitrary code or crash the affected device.