CVE-2019-10600 PUBLISHED CVSS 7.800000190734863 HIGH

Use of local variable as argument to netlink CB callback goes out of it scope when callback triggered lead to invalid stack memory in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCA8081, QCS405, QCS605, QM215, SA6155P, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

EPSS 0.03% · 9.5th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
9.5th percentile

Affected Products

VendorProductVersions
qualcommmdm9650_firmware
qualcommsxr2130_firmware
qualcommsdm439_firmware
qualcommsda845_firmware
qualcommsdx20_firmware
qualcommipq8074_firmware
qualcommqca6574au_firmware
qualcommmsm8939_firmware
qualcommapq8053_firmware
qualcommsdm845_firmware
qualcommsdx55_firmware
qualcommmsm8909w_firmware
qualcommmsm8937_firmware
qualcommsxr1130_firmware
qualcommipq4019_firmware
qualcommqcs405_firmware
qualcommmsm8920_firmware
qualcommsdx24_firmware
qualcommmsm8953_firmware
qualcommsa6155p_firmware

…and 31 more

Timeline

References

Open in Interactive Console →