CVE-2019-2310: High severity android vulnerability
Out of bound read would occur while trying to read action category and action ID without validating the action length of the Rx Frame body in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS605, SDA660, SDA845, SDM450, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM8150
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2310?
CVE-2019-2310 has been classified as a high severity vulnerability due to its potential impact on device security.
How do I fix CVE-2019-2310?
To fix CVE-2019-2310, update the affected Qualcomm firmware to the latest version provided by Qualcomm or the device manufacturer.
Which devices are affected by CVE-2019-2310?
CVE-2019-2310 affects various Qualcomm Snapdragon products, including firmware versions of apq8009, apq8017, apq8053, and many others.
What kind of vulnerability is CVE-2019-2310?
CVE-2019-2310 is an out-of-bounds read vulnerability that occurs when reading action categories and IDs due to improper validation.
When was CVE-2019-2310 disclosed?
CVE-2019-2310 was disclosed in November 2019 as part of a security bulletin addressing vulnerabilities in Qualcomm products.