Time-of-check Time-of-use (TOCTOU) Race Condition in Qualcomm products - CVE-2019-14119

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Qualcomm products - CVE-2019-14119

Published: May 17, 2025


Vulnerability identifier: #VU109331
CSH Severity:
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14119
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.

The vulnerability exists due to improper input validation in QTEE. #AV# #AU# can #EXT_IMPACT#.


Affected software

SA6155P
SXR2130
SXR1130
SM8250
SM8150
SM7150
SM6150
SDX55
SDX24
SDM710
SDM670
SC8180X
Rennell
QCS605
QCS405
Nicobar
MDM9607
Kamorta
SC7180
IPQ6018
SA515M
SA415M
QCS610
QCS404
MDM9205

How to mitigate CVE-2019-14119

Install security update from vendor's website.


External References

Related Security Bulletins