Qualcomm Mdm9206 Firmware Remote Code Execution Vulnerability

Summary

Possibility of double free issue while running multiple instances of smp2p test because of proper protection is missing while using global variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

Credit:

The information has been provided by Joe0x20 
The original article can be found at: https://www.codeaurora.org/security-bulletin/2019/04/01/april-2019-code-aurora-security-bulletin


Details

Qualcomm Mdm9206 Firmware is prone to a remote code-execution vulnerability.This allows a remote attacker to exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts may result in a denial-of-service condition.

Vulnerable Systems:

  • Qualcomm Mdm9150 Firmware
  • Qualcomm Mdm9206 Firmware
  • Qualcomm Mdm9607 Firmware
  • Qualcomm Mdm9640 Firmware
  • Qualcomm Mdm9650 Firmware
  • Qualcomm Msm8909w Firmware
  • Qualcomm Msm8996au Firmware
  • Qualcomm Qcs605 Firmware
  • Qualcomm Qm215 Firmware
  • Qualcomm Sd 205 Firmware
  • Qualcomm Sd 210 Firmware
  • Qualcomm Sd 212 Firmware
  • Qualcomm Sd 415 Firmware
  • Qualcomm Sd 425 Firmware
  • Qualcomm Sd 429 Firmware
  • Qualcomm Sd 439 Firmware
  • Qualcomm Sd 450 Firmware
  • Qualcomm Sd 615 Firmware
  • Qualcomm Sd 616 Firmware
  • Qualcomm Sd 625 Firmware
  • Qualcomm Sd 632 Firmware
  • Qualcomm Sd 636 Firmware
  • Qualcomm Sd 650 Firmware
  • Qualcomm Sd 652 Firmware
  • Qualcomm Sd 670 Firmware
  • Qualcomm Sd 710 Firmware
  • Qualcomm Sd 712 Firmware
  • Qualcomm Sd 820a Firmware
  • Qualcomm Sd 835 Firmware
  • Qualcomm Sd 845 Firmware
  • Qualcomm Sd 850 Firmware
  • Qualcomm Sd 855 Firmware
  • Qualcomm Sda660 Firmware
  • Qualcomm Sdm439 Firmware
  • Qualcomm Sdm630 Firmware
  • Qualcomm Sdm660 Firmware
  • Qualcomm Sdx20 Firmware
  • Qualcomm Sdx24 Firmware

    CVE Information:
    CVE-2019-2247

    Disclosure Timeline:
    Publish Date:05/24/2019