CVE-2019-10545
Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS605, SDM670, SDM710,…
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS605, SDM670, SDM710, SM6150, SM7150, SM8150
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- qualcomm/qcs605 firmware · qualcomm/sdm670 firmware · qualcomm/sdm710 firmware · qualcomm/sm6150 firmware · qualcomm/sm7150 firmware · qualcomm/sm8150 firmware
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/november-2019-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/november-2019-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.