Vulnerability

CVE-2019-10524

Component: VISION
Location: OS
Lack of check for a negative value returned for get_clk is wrongly interpreted as valid pointer and lead to use after free in clk driver in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

Impact

Severity (Manufact.)

N/A

Severity (NIST)

7.8

Severity (Android)

N/A

Chipsets

28

Devices

1411

Affected Hardware

NameAlso known asManufacturer
MSM8909
Snapdragon 210
Qualcomm
MSM8909AA
Snapdragon 212
Qualcomm
QM215
Qualcomm 215
Qualcomm
MSM8917
Snapdragon 425
Qualcomm
MSM8920
Snapdragon 427
Qualcomm
MSM8937
Snapdragon 430
Qualcomm
MSM8940
Snapdragon 435
Qualcomm
SDM429
Snapdragon 429
Qualcomm
SDM439
Snapdragon 439
Qualcomm
SDM450
Snapdragon 450
Qualcomm
28 of 28 row(s) shown.

Rows per page

Page 1 of 3

Timeline

Introduced (est):
Jan 1, 2014
Reported:
Unknown
Advisory Published:
Sep 3, 2019
CVE Published:
Nov 6, 2019
Android Patch Level:
Sep 2019
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter