CVE-2019-2308: High severity Google Android vulnerability
User application could potentially make RPC call to the fastrpc driver and the driver will allow the message to go through to the remote subsystem in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2308?
The severity of CVE-2019-2308 is critical (7.8).
How does CVE-2019-2308 impact users?
CVE-2019-2308 allows user applications to make unauthorized RPC calls to the fastrpc driver, potentially leading to security breaches.
Which products are affected by CVE-2019-2308?
Google Android, Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9607, MDM9650
Is Qualcomm Mdm9150 vulnerable to CVE-2019-2308?
Yes, Qualcomm Mdm9150 is vulnerable to CVE-2019-2308.
How can I fix CVE-2019-2308?
Apply the security patches provided by Google and Qualcomm to fix CVE-2019-2308.