CVE-2019-2326: Out-of-bounds Read
Data token is received from ADSP and is used without validation as an index into the array leads to out of bound access in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2326?
CVE-2019-2326 has been assigned a high severity rating due to potential out-of-bounds access vulnerabilities.
How do I fix CVE-2019-2326?
To fix CVE-2019-2326, it is recommended to update your affected Qualcomm firmware to the latest version that addresses this vulnerability.
Which devices are impacted by CVE-2019-2326?
CVE-2019-2326 affects various Qualcomm chipsets including MDM9150, MDM9206, MDM9607, among others.
What are the potential impacts of CVE-2019-2326?
The potential impacts of CVE-2019-2326 include exploitation leading to abnormal termination of processes or unexpected behavior.
Is CVE-2019-2326 exploitable remotely?
CVE-2019-2326 may be exploitable remotely depending on the configuration and exposure of the affected device.