CVE-2019-14117

HIGH

Snapdragon Auto - Use After Free

Title source: llm
STIX 2.1

Description

u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list which results in a use after free causing an unhandled page fault exception in rmnet driver' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, MDM9607, QCS405, Saipan, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 11.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (11)
qualcomm/bitra_firmware
qualcomm/mdm9607_firmware
qualcomm/qcs405_firmware
qualcomm/saipan_firmware
qualcomm/sc8180x_firmware
qualcomm/sdx55_firmware
qualcomm/sm6150_firmware
qualcomm/sm7150_firmware
qualcomm/sm8150_firmware
qualcomm/sm8250_firmware
... and 1 more
Published Sep 08, 2020
Tracked Since Feb 18, 2026