Integer overflow in Qualcomm products - CVE-2021-1895

 

Integer overflow in Qualcomm products - CVE-2021-1895

Published: May 3, 2021


Vulnerability identifier: #VU52822
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1895
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to integer overflow during system boot when flushing an image. A local user can execute arbitrary code with elevated privileges.


Affected software

SMB1358
WTR2965
WSA8815
WSA8810
WCN3680B
WCN3680
WCN3660B
WCN3615
WCD9330
WCD9326
SMB231
SMB1360
Qualcomm215
QCA9367
PMI8952
PMD9607
PM8953
PM8916
PM8909
PM215
APQ8009
QCA9377
MDM9206
APQ8053

How to mitigate CVE-2021-1895

Install updates from vendor's website.


External References

Related Security Bulletins