CVE-2019-2246

HIGH

Qualcomm Snapdragon - Memory Corruption

Title source: llm
STIX 2.1

Description

Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9205, MDM9640, MSM8996AU, QCA6574, QCS605, Qualcomm 215, SD 425, SD 427, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016, SXR1130

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 26.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (33)
qualcomm/mdm9205_firmware
qualcomm/mdm9640_firmware
qualcomm/msm8996au_firmware
qualcomm/qca6574_firmware
qualcomm/qcs605_firmware
qualcomm/qualcomm_215_firmware
qualcomm/sd_425_firmware
qualcomm/sd_427_firmware
qualcomm/sd_429_firmware
qualcomm/sd_435_firmware
... and 23 more
Published Nov 06, 2019
Tracked Since Feb 18, 2026