CVE-2018-3589: Qualcomm MDM9650 Firmware

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile MDM9650, MDM9655, SD 835, SD 845, SD 850, the vswr capture size is larger than the maximum size of a diag logPacket, which can lead to a buffer overflow when the sample buffer is copied to the logPacket buffer.

Affected products

  • Qualcomm MDM9650 Firmware: affected versions not specified
  • Qualcomm MDM9655 Firmware: affected versions not specified
  • Qualcomm Sd 835 Firmware: affected versions not specified
  • Qualcomm Sd 845 Firmware: affected versions not specified
  • Qualcomm Sd 850 Firmware: affected versions not specified

Published 2018-04-11. Last modified 2026-06-17.