CVE-2019-10529 EXPLOIT
8.1
HIGH · CVSS 3.1 · EPSS 1.7% (pctl 77)
Patch early
A public exploit exists.
Description
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.74% — more likely to be exploited than 77% of all CVEs |
| Weakness | CWE-362 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-11-06 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| qualcomm | mdm9150 |
| qualcomm | mdm9150 firmware |
| qualcomm | mdm9206 |
| qualcomm | mdm9206 firmware |
| qualcomm | mdm9607 |
| qualcomm | mdm9607 firmware |
| qualcomm | mdm9640 |
| qualcomm | mdm9640 firmware |
| qualcomm | mdm9650 |
| qualcomm | mdm9650 firmware |
| qualcomm | msm8909w |
| qualcomm | msm8909w firmware |
| qualcomm | msm8996au |
| qualcomm | msm8996au firmware |
| qualcomm | qcs405 |
| qualcomm | qcs405 firmware |
| qualcomm | qcs605 |
| qualcomm | qcs605 firmware |
| qualcomm | qualcomm 215 |
| qualcomm | qualcomm 215 firmware |
| qualcomm | sd 205 |
| qualcomm | sd 205 firmware |
| qualcomm | sd 210 |
| qualcomm | sd 210 firmware |
| qualcomm | sd 212 |
| qualcomm | sd 212 firmware |
| qualcomm | sd 415 |
| qualcomm | sd 415 firmware |
| qualcomm | sd 425 |
| qualcomm | sd 425 firmware |
| qualcomm | sd 429 |
| qualcomm | sd 429 firmware |
| qualcomm | sd 439 |
| qualcomm | sd 439 firmware |
| qualcomm | sd 450 |
| qualcomm | sd 450 firmware |
| qualcomm | sd 615 |
| qualcomm | sd 615 firmware |
| qualcomm | sd 616 |
| qualcomm | sd 616 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Qualcomm Android - Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL | 2019-05-29 |
References
→ the Explorer · watch your stack · NVD