CVE-2019-2346: Out-of-bounds Read
Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation. in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ8074, QCA8081, QCS404, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-2346?
CVE-2019-2346 is a vulnerability in Qualcomm IPQ8074 firmware that allows for a loop of overwriting memory when a scan command is given from the host due to improper validation.
Which software is affected by CVE-2019-2346?
Google Android and Qualcomm IPQ8074 firmware are affected by CVE-2019-2346.
What is the severity of CVE-2019-2346?
CVE-2019-2346 has a severity of 7.8 (high).
How can I fix CVE-2019-2346?
To fix CVE-2019-2346, it is recommended to apply the latest security updates provided by Google and Qualcomm.
Where can I find more information about CVE-2019-2346?
You can find more information about CVE-2019-2346 on the Qualcomm and Android security bulletins.