CVE-2019-14105

HIGH

Snapdragon Industrial IOT/Snapdragon Mobile - Memory Overflow

Title source: llm
STIX 2.1

Description

Kernel was reading the CSL defined reserved field as uint16 instead of uint32 which could lead to memory overflow in Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SM8150

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (3)
qualcomm/sda845_firmware
qualcomm/sdm845_firmware
qualcomm/sm8150_firmware
Published Apr 16, 2020
Tracked Since Feb 18, 2026