CRITICAL · 9.8

CVE-2019-2249

Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon M...

Vulnerability Description

Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9205, MDM9650, QCA8081, QCS605, SD 427, SD 435, SD 450, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX20, Snapdragon_High_Med_2016, SXR1130

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommIpq8074 Firmware-
QualcommIpq8074-
QualcommMdm9205 Firmware-
QualcommMdm9205-
QualcommMdm9650 Firmware-
QualcommMdm9650-
QualcommQca8081 Firmware-
QualcommQca8081-
QualcommQcs605 Firmware-
QualcommQcs605-
QualcommSd 427 Firmware-
QualcommSd 427-
QualcommSd 435 Firmware-
QualcommSd 435-
QualcommSd 450 Firmware-
QualcommSd 450-
QualcommSd 625 Firmware-
QualcommSd 625-
QualcommSd 636 Firmware-
QualcommSd 636-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-2249?

CVE-2019-2249 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon M...

How severe is CVE-2019-2249?

CVE-2019-2249 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-2249?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ipq8074 Firmware, Qualcomm Ipq8074, Qualcomm Mdm9205 Firmware, Qualcomm Mdm9205, Qualcomm Mdm9650 Firmware.