Vulnerabilities > CVE-2019-10529 - Use After Free vulnerability in Qualcomm products

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
qualcomm
CWE-416
exploit available

Summary

Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

Vulnerable Configurations

Part Description Count
OS
Qualcomm
41
Hardware
Qualcomm
41

Common Weakness Enumeration (CWE)

Exploit-Db

idEDB-ID:46941
last seen2019-05-29
modified2019-05-29
published2019-05-29
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46941
titleQualcomm Android - Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL