### [CVE-2019-2339](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2339) ![](https://img.shields.io/static/v1?label=Product&message=Snapdragon%20Auto%2C%20Snapdragon%20Compute%2C%20Snapdragon%20Connectivity%2C%20Snapdragon%20Consumer%20IOT%2C%20Snapdragon%20Industrial%20IOT%2C%20Snapdragon%20Mobile%2C%20Snapdragon%20Wired%20Infrastructure%20and%20Networking&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Restriction%20of%20Operation%20Within%20the%20Bounds%20of%20Memory%20in%20QTEE&color=brighgreen) ### Description Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130 ### POC #### Reference - https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletin - https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletin #### Github No PoCs found on GitHub currently.