CVE-2019-2302: Integer Overflow
While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead to heap overflow. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8976, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS405, QCS605, SDA845, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM8150
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2302?
CVE-2019-2302 has a high severity rating due to the potential for a heap overflow resulting from an integer overflow.
How do I fix CVE-2019-2302?
To mitigate CVE-2019-2302, users should apply the latest firmware updates provided by Qualcomm for the affected devices.
Which devices are affected by CVE-2019-2302?
CVE-2019-2302 affects multiple Qualcomm chipsets including APQ8017, APQ8053, APQ8096AU, and MDM9206 among others.
What is the impact of CVE-2019-2302?
The impact of CVE-2019-2302 includes potential arbitrary code execution and denial of service due to heap overflow.
Is CVE-2019-2302 being actively exploited?
As of the latest reports, there have been no confirmed active exploits targeting CVE-2019-2302.