CVE-2019-2266
Last modified
CVE-2019-2266 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MSM8909, MSM8909W, Nicobar, QCA9980, QCS405, QCS605, SDM845, SDX24, SM7150, SM8150. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MSM8909, MSM8909W, Nicobar, QCA9980, QCS405, QCS605, SDM845, SDX24, SM7150, SM8150
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Apq8053 Firmware | All versions |
| Qualcomm | Ipq4019 Firmware | All versions |
| Qualcomm | Ipq8064 Firmware | All versions |
| Qualcomm | Mdm9206 Firmware | All versions |
| Qualcomm | Mdm9207c Firmware | All versions |
| Qualcomm | Mdm9607 Firmware | All versions |
| Qualcomm | Msm8909 Firmware | All versions |
| Qualcomm | Msm8909w Firmware | All versions |
| Qualcomm | Nicobar Firmware | All versions |
| Qualcomm | Qca9980 Firmware | All versions |
| Qualcomm | Qcs405 Firmware | All versions |
| Qualcomm | Qcs605 Firmware | All versions |
| Qualcomm | Sdm845 Firmware | All versions |
| Qualcomm | Sdx24 Firmware | All versions |
| Qualcomm | Sm7150 Firmware | All versions |
| Qualcomm | Sm8150 Firmware | All versions |
References
- https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletinPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-2266?
How severe is CVE-2019-2266?
How do I fix CVE-2019-2266?
Are you affected by CVE-2019-2266?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
