NULL pointer dereference in Qualcomm products - CVE-2021-1946

 

NULL pointer dereference in Qualcomm products - CVE-2021-1946

Published: September 6, 2021


Vulnerability identifier: #VU56342
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1946
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a NULL pointer dereference error while processing crafted SDP body within the Data Modem component. A remote attacker can send specially crafted data to the system and execute arbitrary code.


Affected software

SDX55
SD855
SD730
QCA9377
QCA6574AU
QCA6174A
MSM8953
MSM8940
MSM8920
MSM8917
APQ8053
SD665
SD450
SD210
SD205
APQ8017
SD675
WCD9371
WCD9370
WCD9360
WCD9341
WCD9340
WCD9335
SM7325
SM7250
SM6250P
SM6250
SDXR25G
SDX55M
WCD9375
SDX12
SD8885G
SD870
SD8655G
SD780G
SD778G
SD768G
SD765G
SD765
SD750G
WCN3991
WSA8835
WSA8830
WSA8815
WHS9410
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCN6740
WCN3998
WCN3990
WCN3988
WCN3980
WCN3950
WCN3910
WCN3680
WCN3660B
WCN3660
WCN3610
WCD9385
WCD9380
QCA6421
QCM4290
QCA8337
QCA6696
QCA6595AU
QCA6574A
QCA6436
QCA6431
QCA6430
QCA6426
QCM6125
QCA6420
QCA6391
QCA6390
AR8035
AQT1000
SD8C
SD720G
SD6905G
SD678
SD632
SD480
SD429
SD8CX
SA8155P
SA8155
Qualcomm215
QSM8350
QCS6490
QCS6125
QCS610
QCS4290
QCS410
QCM6490
Google Android

How to mitigate CVE-2021-1946

Install updates from vendor's website.

Google Android - addressed in versions 8.1 2021-09-05, 9 2021-09-05, 10 2021-09-05, 11 2021-09-05

External References

Related Security Bulletins