CVE-2019-2306: Incorrect Type Cast
Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2306?
CVE-2019-2306 is classified as a high-severity vulnerability due to its potential for buffer over-read and exposure of sensitive information.
How do I fix CVE-2019-2306?
To fix CVE-2019-2306, users should update their Qualcomm firmware to the latest version that addresses the vulnerability.
What devices are affected by CVE-2019-2306?
CVE-2019-2306 affects various Qualcomm Snapdragon platforms, including MDM9150, MDM9206, MDM9607, and others.
What impact can CVE-2019-2306 have on my device?
If exploited, CVE-2019-2306 can lead to unauthorized access to sensitive data through buffer over-read vulnerabilities.
Is CVE-2019-2306 being actively exploited in the wild?
As of now, there is no public indication that CVE-2019-2306 is being actively exploited, but users are advised to apply updates as a precaution.