First published: Mon Oct 07 2019(Updated: )
Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8017, APQ8053, APQ8096, APQ8096AU, IPQ8074, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, QCA8081, QM215, SDM429, SDM439, SDM450, SDM632, Snapdragon_High_Med_2016
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Qualcomm Apq8017 Firmware | ||
Qualcomm Apq8017 | ||
Qualcomm Apq8053 Firmware | ||
Qualcomm Apq8053 | ||
Qualcomm Apq8096 Firmware | ||
Google Android | ||
Qualcomm Apq8096au Firmware | ||
Qualcomm Apq8096au | ||
Qualcomm Ipq8074 Firmware | ||
Qualcomm Ipq8074 | ||
Qualcomm Msm8917 Firmware | ||
Qualcomm Msm8917 | ||
Qualcomm Msm8920 Firmware | ||
Qualcomm Msm8920 | ||
Qualcomm Msm8937 Firmware | ||
Qualcomm Msm8937 | ||
Qualcomm Msm8940 Firmware | ||
Qualcomm Msm8940 | ||
Qualcomm Msm8953 Firmware | ||
Qualcomm Msm8953 | ||
Qualcomm Msm8996 Firmware | ||
Google Android | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Qca8081 Firmware | ||
Qualcomm Qca8081 | ||
Qualcomm Qm215 Firmware | ||
Qualcomm Qm215 | ||
Qualcomm Sdm429 Firmware | ||
Qualcomm Sdm429 | ||
Qualcomm Sdm439 Firmware | ||
Qualcomm Sdm439 | ||
Qualcomm Sdm450 Firmware | ||
Qualcomm SDM450 | ||
Qualcomm Sdm632 Firmware | ||
Qualcomm Sdm632 | ||
Qualcomm Snapdragon High Med 2016 Firmware | ||
Qualcomm Snapdragon High Med 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-2318.
The severity of CVE-2019-2318 is high with a CVSS score of 5.5.
CVE-2019-2318 affects Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in various Qualcomm processors.
CVE-2019-2318 can result in a DoS attack by causing Trustzone to perform an arbitrary memory read.
You can find more information about CVE-2019-2318 in the October 2019 bulletin by Qualcomm and the Android security bulletin of October 2019.