ZeroHour

CVE-2018-11942

CVSS 3.0
5.5 medium
EPSS
<1%p9
Published
()
Modified
Description

Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialized kernel SKB memory to FW in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24

Vendors
qualcomm
Products
ipq4019 firmware, ipq8064 firmware, ipq8074 firmware, mdm9150 firmware, mdm9206 firmware, mdm9607 firmware, mdm9640 firmware, mdm9650 firmware, msm8996au firmware, qcs405 firmware, qcs605 firmware, sd 425 firmware
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.