Vulnerability

CVE-2019-10490

Component: POSITION
Location: OS
Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, SDA660, SDA845, SDM450, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150, SM8250, SXR2130

Impact

Severity (Manufact.)

N/A

Severity (NIST)

5.5

Severity (Android)

N/A

Chipsets

19

Devices

1225

Affected Hardware

NameAlso known asManufacturer
MSM8905
Qualcomm 205
Qualcomm
MSM8909
Snapdragon 210
Qualcomm
MSM8917
Snapdragon 425
Qualcomm
MSM8920
Snapdragon 427
Qualcomm
MSM8937
Snapdragon 430
Qualcomm
MSM8940
Snapdragon 435
Qualcomm
SDM450
Snapdragon 450
Qualcomm
MSM8939
Snapdragon 615
Qualcomm
MSM8953
Snapdragon 625
Qualcomm
SDM660
Snapdragon 660
Qualcomm
19 of 19 row(s) shown.

Rows per page

Page 1 of 2

Timeline

Introduced (est):
Jan 1, 2014
Reported:
Unknown
Advisory Published:
Oct 7, 2019
CVE Published:
Nov 21, 2019
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter