Integer overflow in Qualcomm products - CVE-2019-14056
Published: May 17, 2025
Vulnerability identifier: #VU109326
CSH Severity:
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14056
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.
The vulnerability exists due to improper input validation in TrustZone. #AV# #AU# can #EXT_IMPACT#.
Affected software
SDA660
SXR2130
SXR1130
SM8150
SM7150
SM6150
SDX55
SDM845
SDM710
SDM670
SDM660
SDM636
SDM630
SDA845
Kamorta
SC8180X
SA6155P
Rennell
QCS605
QCS405
Nicobar
MDM9650
MDM9607
MDM9150
SDM850
SC7180
QCS610
QCS404
MDM9205
SXR2130
SXR1130
SM8150
SM7150
SM6150
SDX55
SDM845
SDM710
SDM670
SDM660
SDM636
SDM630
SDA845
Kamorta
SC8180X
SA6155P
Rennell
QCS605
QCS405
Nicobar
MDM9650
MDM9607
MDM9150
SDM850
SC7180
QCS610
QCS404
MDM9205
How to mitigate CVE-2019-14056
Install security update from vendor's website.