SB2023120433 - Multiple vulnerabilities in MediaTek chipsets
Published: December 4, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 30 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2023-32847)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within audio. A local application can execute arbitrary code.
2) Incorrect Comparison (CVE-ID: CVE-2023-32848)
CWE-ID: CWE-697 - Incorrect Comparison
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to type confusion within vdec. A local privileged application can execute arbitrary code.
3) Integer underflow (CVE-ID: CVE-2023-32850)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to an integer overflow within decoder. A local application can execute arbitrary code.
4) Incorrect Calculation of Buffer Size (CVE-ID: CVE-2023-32851)
CWE-ID: CWE-131 - Incorrect Calculation of Buffer Size
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within decoder. A local application can execute arbitrary code.
5) Incorrect Comparison (CVE-ID: CVE-2023-32849)
CWE-ID: CWE-697 - Incorrect Comparison
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to type confusion within cmdq. A local privileged application can execute arbitrary code.
6) Improper input validation (CVE-ID: CVE-2023-32852)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to gain access to sensitive information.
The vulnerability exists due to improper input validation within cameraisp. A local privileged application can gain access to sensitive information.
7) Out-of-bounds write (CVE-ID: CVE-2023-32853)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within rpmb. A local privileged application can execute arbitrary code.
8) Out-of-bounds write (CVE-ID: CVE-2023-32854)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within ril. A local privileged application can execute arbitrary code.
9) Buffer overflow (CVE-ID: CVE-2023-32855)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing permission check within aee. A local privileged application can execute arbitrary code.
10) Buffer overflow (CVE-ID: CVE-2023-32856)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to gain access to sensitive information.
The vulnerability exists due to an incorrect status check within display. A local privileged application can gain access to sensitive information.
11) Buffer overflow (CVE-ID: CVE-2023-32857)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to gain access to sensitive information.
The vulnerability exists due to an incorrect status check within display. A local privileged application can gain access to sensitive information.
12) Information exposure (CVE-ID: CVE-2023-32858)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to gain access to sensitive information.
The vulnerability exists due to a missing data erasing within GZ. A local privileged application can gain access to sensitive information.
13) Reachable Assertion (CVE-ID: CVE-2023-32841)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper error handling within 5G Modem. A local application can perform service disruption.
14) Reachable Assertion (CVE-ID: CVE-2023-32842)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper error handling within 5G Modem. A local application can perform service disruption.
15) Reachable Assertion (CVE-ID: CVE-2023-32843)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper error handling within 5G Modem. A local application can perform service disruption.
16) Reachable Assertion (CVE-ID: CVE-2023-32845)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper error handling within 5G Modem. A local application can perform service disruption.
17) Reachable Assertion (CVE-ID: CVE-2023-32844)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper error handling within 5G Modem. A local application can perform service disruption.
18) Reachable Assertion (CVE-ID: CVE-2023-32846)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper error handling within 5G Modem. A local application can perform service disruption.
19) Buffer overflow (CVE-ID: CVE-2023-32859)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within meta. A local privileged application can execute arbitrary code.
20) Buffer overflow (CVE-ID: CVE-2023-32860)
CWE-ID: CWE-120 - Buffer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within display. A local privileged application can execute arbitrary code.
21) Out-of-bounds read (CVE-ID: CVE-2023-32861)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within display. A local privileged application can execute arbitrary code.
22) Out-of-bounds read (CVE-ID: CVE-2023-32862)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within display. A local privileged application can execute arbitrary code.
23) Out-of-bounds read (CVE-ID: CVE-2023-32863)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within display drm. A local privileged application can execute arbitrary code.
24) Out-of-bounds write (CVE-ID: CVE-2023-32864)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within display drm. A local privileged application can execute arbitrary code.
25) Out-of-bounds write (CVE-ID: CVE-2023-32865)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within display drm. A local privileged application can execute arbitrary code.
26) Out-of-bounds write (CVE-ID: CVE-2023-32866)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within mmp. A local privileged application can execute arbitrary code.
27) Out-of-bounds write (CVE-ID: CVE-2023-32867)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within display drm. A local privileged application can execute arbitrary code.
28) Out-of-bounds write (CVE-ID: CVE-2023-32868)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within display drm. A local privileged application can execute arbitrary code.
29) Out-of-bounds write (CVE-ID: CVE-2023-32869)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within display drm. A local privileged application can execute arbitrary code.
30) Out-of-bounds read (CVE-ID: CVE-2023-32870)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within display drm. A local privileged application can execute arbitrary code.
Remediation
Install update from vendor's website.