CVE-2019-2324

When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary access in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 845 / SD 850, SD 855, SDX20, SDX24
References
Link Resource
https://source.android.com/security/bulletin/ Patch Vendor Advisory
Configurations

Configuration 1


Information

Published : 2019-11-06 05:15

Updated : 2019-11-08 03:07


NVD link : CVE-2019-2324

Mitre link : CVE-2019-2324

Products Affected
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer