CVE-2019-2328: Buffer Overflow
Possible buffer overflow when number of channels passed is more than size of channel mapping array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-2328?
CVE-2019-2328 is a vulnerability that may lead to a buffer overflow when the number of channels passed is more than the size of the channel mapping array in various Qualcomm products.
How severe is CVE-2019-2328?
CVE-2019-2328 has a severity keyword of 'high' with a CVSS score of 7.8.
Which products are affected by CVE-2019-2328?
Products affected by CVE-2019-2328 include Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables in various Qualcomm firmware versions.
Are Google Android devices vulnerable to CVE-2019-2328?
Yes, Google Android devices with certain Qualcomm firmware versions are vulnerable to CVE-2019-2328.
How can I mitigate the risk of CVE-2019-2328?
To mitigate the risk of CVE-2019-2328, ensure that the number of channels passed does not exceed the size of the channel mapping array in the affected Qualcomm products.