MEDIUM · 5.5

CVE-2019-10520

An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & M...

Vulnerability Description

An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 210/SD 212/SD 205, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommQcs405 Firmware-
QualcommQcs405-
QualcommSd 210 Firmware-
QualcommSd 210-
QualcommSd 212 Firmware-
QualcommSd 212-
QualcommSd 205 Firmware-
QualcommSd 205-
QualcommSd 665 Firmware-
QualcommSd 665-
QualcommSd 675 Firmware-
QualcommSd 675-
QualcommSd 712 Firmware-
QualcommSd 712-
QualcommSd 710 Firmware-
QualcommSd 710-
QualcommSd 670 Firmware-
QualcommSd 670-
QualcommSd 730 Firmware-
QualcommSd 730-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10520?

CVE-2019-10520 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & M...

How severe is CVE-2019-10520?

CVE-2019-10520 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10520?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Qcs405 Firmware, Qualcomm Qcs405, Qualcomm Sd 210 Firmware, Qualcomm Sd 210, Qualcomm Sd 212 Firmware.