CVE-2019-10520
An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 210/SD 212/SD 205, SD 665, SD 675,…
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 210/SD 212/SD 205, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-772
- Affected
- qualcomm/qcs405 firmware · qualcomm/sd 210 firmware · qualcomm/sd 212 firmware · qualcomm/sd 205 firmware · qualcomm/sd 665 firmware · qualcomm/sd 675 firmware · qualcomm/sd 712 firmware · qualcomm/sd 710 firmware · qualcomm/sd 670 firmware · qualcomm/sd 730 firmware · qualcomm/sd 845 firmware · qualcomm/sd 850 firmware · qualcomm/sd 855 firmware
- Source
- product-security@qualcomm.com
References
- https://source.android.com/security/bulletin/pixel/2019-11-01Patch, Third Party Advisory
- https://source.android.com/security/bulletin/pixel/2019-11-01Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.