CVE-2019-10581

CRITICAL

Qualcomm Snapdragon Firmware - Use-After-Free in Audio Device Pointer Handling

Title source: llm
STIX 2.1

Description

NULL is assigned to local instance of audio device pointer after free instead of global static pointer and can lead to use after free issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, MDM9206, MDM9207C, MDM9607, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8998, Nicobar, QCS605, Rennell, SA6155P, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 60.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (28)
qualcomm/apq8009_firmware
qualcomm/apq8053_firmware
qualcomm/mdm9206_firmware
qualcomm/mdm9207c_firmware
qualcomm/mdm9607_firmware
qualcomm/msm8909w_firmware
qualcomm/msm8917_firmware
qualcomm/msm8920_firmware
qualcomm/msm8937_firmware
qualcomm/msm8940_firmware
... and 18 more
Published Jan 21, 2020
Tracked Since Feb 18, 2026