CVE-2019-10506
HIGHQualcomm Multiple Chipsets Firmware - Improper Input Validation in QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY
Title source: llmDescription
While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
References (1)
Core 1
Core References
Patch, Third Party Advisory x_refsource_confirm
https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletin
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
13.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (26)
qualcomm/mdm9206_firmware
qualcomm/mdm9607_firmware
qualcomm/msm8996au_firmware
qualcomm/qca6174a_firmware
qualcomm/qca6574au_firmware
qualcomm/qca9377_firmware
qualcomm/qca9379_firmware
qualcomm/qcs605_firmware
qualcomm/sd_600_firmware
qualcomm/sd_625_firmware
... and 16 more
Published
Sep 30, 2019
Tracked Since
Feb 18, 2026