Description
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, SD 400, SD 425, SD 430, SD 450, SD 600, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, in the Diag User-PD command registration function, a length variable used during buffer allocation is not checked, so if it is very large, an integer overflow followed by a buffer overflow occurs.
Published: 2018-04-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2015-9001 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, SD 400, SD 425, SD 430, SD 450, SD 600, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, in the Diag User-PD command registration function, a length variable used during buffer allocation is not checked, so if it is very large, an integer overflow followed by a buffer overflow occurs.
History

No history.

Subscriptions

Qualcomm Mdm9625 Mdm9625 Firmware Mdm9635m Mdm9635m Firmware Mdm9640 Mdm9640 Firmware Mdm9645 Mdm9645 Firmware Mdm9650 Mdm9650 Firmware Mdm9655 Mdm9655 Firmware Sd 400 Sd 400 Firmware Sd 425 Sd 425 Firmware Sd 430 Sd 430 Firmware Sd 450 Sd 450 Firmware Sd 600 Sd 600 Firmware Sd 617 Sd 617 Firmware Sd 625 Sd 625 Firmware Sd 650 Sd 650 Firmware Sd 652 Sd 652 Firmware Sd 800 Sd 800 Firmware Sd 808 Sd 808 Firmware Sd 810 Sd 810 Firmware Sd 820 Sd 820 Firmware Sd 820a Sd 820a Firmware Sd 835 Sd 835 Firmware Sd 845 Sd 845 Firmware Sd 850 Sd 850 Firmware Sdx20 Sdx20 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-09-17T04:25:15.573Z

Reserved: 2017-08-16T00:00:00.000Z

Link: CVE-2015-9148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-18T14:29:05.027

Modified: 2024-11-21T02:39:54.443

Link: CVE-2015-9148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses