CVE-2019-14088

Possible use after free issue while CRM is accessing the link pointer from device private data due to lack of resource protection in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, MDM9206, MDM9207C, MDM9607, QCS605, SDM429W, SDX24, SM8150, SXR1130
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:apq8009_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8009:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:mdm9207c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:mdm9207c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs605:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:sdm429w_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdm429w:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:sdx24_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdx24:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:sm8150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm8150:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:sxr1130_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr1130:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:26

Type Values Removed Values Added
References () https://www.qualcomm.com/company/product-security/bulletins/february-2020-bulletin - Patch, Vendor Advisory () https://www.qualcomm.com/company/product-security/bulletins/february-2020-bulletin - Patch, Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-20-199/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-20-199/ - Third Party Advisory, VDB Entry

Information

Published : 2020-02-07 05:15

Updated : 2024-11-21 04:26


NVD link : CVE-2019-14088

Mitre link : CVE-2019-14088

CVE.ORG link : CVE-2019-14088


JSON object : View

Products Affected

qualcomm

  • apq8009_firmware
  • mdm9206_firmware
  • sdm429w_firmware
  • sxr1130
  • qcs605_firmware
  • mdm9607_firmware
  • sdx24_firmware
  • sm8150
  • mdm9206
  • sxr1130_firmware
  • mdm9207c
  • apq8009
  • sdm429w
  • qcs605
  • mdm9607
  • mdm9207c_firmware
  • sdx24
  • sm8150_firmware
CWE
CWE-416

Use After Free