Vulnerability Description
Kernel memory error in debug module due to improper check of user data length before copying into memory in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ8098, MSM8996AU, QCN7605, SDM439, SDX24, SM8150
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Apq8096Au Firmware | - |
| Qualcomm | Apq8096Au | - |
| Qualcomm | Apq8098 Firmware | - |
| Qualcomm | Apq8098 | - |
| Qualcomm | Msm8996Au Firmware | - |
| Qualcomm | Msm8996Au | - |
| Qualcomm | Qcn7605 Firmware | - |
| Qualcomm | Qcn7605 | - |
| Qualcomm | Sdm439 Firmware | - |
| Qualcomm | Sdm439 | - |
| Qualcomm | Sdx24 Firmware | - |
| Qualcomm | Sdx24 | - |
| Qualcomm | Sm8150 Firmware | - |
| Qualcomm | Sm8150 | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/april-2020-bulletinPatchVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/april-2020-bulletinPatchVendor Advisory
FAQ
What is CVE-2019-10620?
CVE-2019-10620 is a vulnerability with a CVSS score of 7.8 (HIGH). Kernel memory error in debug module due to improper check of user data length before copying into memory in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snap...
How severe is CVE-2019-10620?
CVE-2019-10620 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10620?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Apq8096Au Firmware, Qualcomm Apq8096Au, Qualcomm Apq8098 Firmware, Qualcomm Apq8098, Qualcomm Msm8996Au Firmware.