Vulnerability Description
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Mdm9607 Firmware | - |
| Qualcomm | Mdm9607 | - |
| Qualcomm | Msm8996Au Firmware | - |
| Qualcomm | Msm8996Au | - |
| Qualcomm | Qca6174A Firmware | - |
| Qualcomm | Qca6174A | - |
| Qualcomm | Qca6574Au Firmware | - |
| Qualcomm | Qca6574Au | - |
| Qualcomm | Qca9377 Firmware | - |
| Qualcomm | Qca9377 | - |
| Qualcomm | Qca9379 Firmware | - |
| Qualcomm | Qca9379 | - |
| Qualcomm | Qcs405 Firmware | - |
| Qualcomm | Qcs405 | - |
| Qualcomm | Qcs605 Firmware | - |
| Qualcomm | Qcs605 | - |
| Qualcomm | Sd 636 Firmware | - |
| Qualcomm | Sd 636 | - |
| Qualcomm | Sd 665 Firmware | - |
| Qualcomm | Sd 665 | - |
Related Weaknesses (CWE)
References
- https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-sePatchThird Party Advisory
- https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-sePatchThird Party Advisory
FAQ
What is CVE-2019-2276?
CVE-2019-2276 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Conne...
How severe is CVE-2019-2276?
CVE-2019-2276 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-2276?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Mdm9607 Firmware, Qualcomm Mdm9607, Qualcomm Msm8996Au Firmware, Qualcomm Msm8996Au, Qualcomm Qca6174A Firmware.