ZeroHour

CVE-2019-2314

CVSS 3.0
7.0 high
EPSS
<1%p3
Published
()
Modified
Description

Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855, SDM439, SDM660, SDX20, SDX24

Vendors
qualcomm
Products
msm8909w firmware, qcs405 firmware, qcs605 firmware, qualcomm 215 firmware, sd 425 firmware, sd 439 firmware, sd 429 firmware, sd 450 firmware, sd 625 firmware, sd 632 firmware, sd 636 firmware, sd 665 firmware
Weakness
CWE-362, CWE-416
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.