CWE
125
Advisory Published
Updated

CVE-2019-2318

First published: Mon Oct 07 2019(Updated: )

Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8017, APQ8053, APQ8096, APQ8096AU, IPQ8074, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, QCA8081, QM215, SDM429, SDM439, SDM450, SDM632, Snapdragon_High_Med_2016

Credit: product-security@qualcomm.com

Affected SoftwareAffected VersionHow to fix
Google Android
Qualcomm Apq8017 Firmware
Qualcomm Apq8017
Qualcomm Apq8053 Firmware
Qualcomm Apq8053
Qualcomm Apq8096 Firmware
Google Android
Qualcomm Apq8096au Firmware
Qualcomm Apq8096au
Qualcomm Ipq8074 Firmware
Qualcomm Ipq8074
Qualcomm Msm8917 Firmware
Qualcomm Msm8917
Qualcomm Msm8920 Firmware
Qualcomm Msm8920
Qualcomm Msm8937 Firmware
Qualcomm Msm8937
Qualcomm Msm8940 Firmware
Qualcomm Msm8940
Qualcomm Msm8953 Firmware
Qualcomm Msm8953
Qualcomm Msm8996 Firmware
Google Android
Qualcomm Msm8996au Firmware
Qualcomm Msm8996au
Qualcomm Qca8081 Firmware
Qualcomm Qca8081
Qualcomm Qm215 Firmware
Qualcomm Qm215
Qualcomm Sdm429 Firmware
Qualcomm Sdm429
Qualcomm Sdm439 Firmware
Qualcomm Sdm439
Qualcomm Sdm450 Firmware
Qualcomm SDM450
Qualcomm Sdm632 Firmware
Qualcomm Sdm632
Qualcomm Snapdragon High Med 2016 Firmware
Qualcomm Snapdragon High Med 2016

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the vulnerability ID of this issue?

    The vulnerability ID is CVE-2019-2318.

  • What is the severity of CVE-2019-2318?

    The severity of CVE-2019-2318 is high with a CVSS score of 5.5.

  • Which products are affected by CVE-2019-2318?

    CVE-2019-2318 affects Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in various Qualcomm processors.

  • How can CVE-2019-2318 result in a denial-of-service (DoS) attack?

    CVE-2019-2318 can result in a DoS attack by causing Trustzone to perform an arbitrary memory read.

  • Where can I find more information about CVE-2019-2318?

    You can find more information about CVE-2019-2318 in the October 2019 bulletin by Qualcomm and the Android security bulletin of October 2019.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203