CVE-2019-2311: Buffer Overflow
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8996, MSM8996AU, MSM8998, QCA6174A, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA8081, QCA9377, QCA9379, QCA9886, QCS605, SA6155P, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2311?
The severity of CVE-2019-2311 is classified as critical, as it involves a buffer overflow that could lead to remote code execution.
How do I fix CVE-2019-2311?
To fix CVE-2019-2311, apply the latest security patches provided by Qualcomm or the device manufacturer.
Which devices are affected by CVE-2019-2311?
CVE-2019-2311 affects various Qualcomm Snapdragon devices, including models in automotive, mobile, and IoT categories.
Can CVE-2019-2311 be exploited remotely?
Yes, CVE-2019-2311 can be exploited remotely through specially crafted WLAN requests that trigger the buffer overflow.
Is there a workaround for CVE-2019-2311?
Currently, the best practice is to update the affected firmware as there are no recommended workarounds for CVE-2019-2311.