Integer overflow in Qualcomm products - CVE-2019-14074

 

Integer overflow in Qualcomm products - CVE-2019-14074

Published: May 17, 2025


Vulnerability identifier: #VU109328
CSH Severity:
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14074
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.

The vulnerability exists due to improper input validation in Diag Services. #AV# #AU# can #EXT_IMPACT#.


Affected software

Saipan
SDM450
SDM439
SDM429W
SDM429
SDA845
SDA660
SC8180X
SDM630
SA6155P
Rennell
QM215
QCS605
QCS405
SDX20
SXR2130
SXR1130
SM8250
SM8150
SM7150
SM6150
SDX55
SDX24
QCN7605
SDM845
SDM710
SDM670
SDM660
SDM636
SDM632
Kamorta
MDM9640
MDM9607
MDM9207C
MDM9206
MDM9150
IPQ8074
APQ8098
APQ8096AU
APQ8053
APQ8017
MSM8937
QCM2150
Nicobar
MSM8998
MSM8996AU
MSM8996
MSM8953
MSM8940
APQ8009
MSM8920
MSM8917
MSM8909W
MSM8905
MDM9650
SC7180
SA415M
QCS610
QCS404
SDM850
MDM9635M
MDM9625
MDM9205
MDM9645
IPQ6018
Bitra
APQ8076
QCA8081
MSM8909
MDM9655

How to mitigate CVE-2019-14074

Install security update from vendor's website.


External References

Related Security Bulletins