Vulnerability

CVE-2018-11955

Component: WIFI
Location: OS
Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame and results in out of bound read in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 665, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDM660, SDX20, SDX24

Impact

Severity (Manufact.)

N/A

Severity (NIST)

9.8

Severity (Android)

N/A

Chipsets

4

Devices

136

Affected Hardware

NameAlso known asManufacturer
SDM439
Snapdragon 439
Qualcomm
SDM660
Snapdragon 660
Qualcomm
MSM8909w
Wear 2100
Wear 2500
Wear 3100
Qualcomm
MSM8996AU
Snapdragon 820A
Qualcomm
4 of 4 row(s) shown.

Rows per page

Page 1 of 1

Timeline

Introduced (est):
Apr 1, 2017
Reported:
Unknown
Advisory Published:
N/A
CVE Published:
Jun 14, 2019
Android Patch Level:
May 2019
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter