Out-of-bounds read in Qualcomm products - CVE-2021-1981

 

Out-of-bounds read in Qualcomm products - CVE-2021-1981

Published: November 3, 2021


Vulnerability identifier: #VU57905
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1981
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper IE size check of Bearer capability IE in MT setup request from network. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.


Affected software

SM7325
WCD9385
WCD9380
WCD9375
WCD9371
WCD9370
WCD9360
WCD9341
WCD9340
WCD9326
SM8450P
SM8450
WCN3610
SM7250
SM6375
SM6250P
SM6250
SDXR2 5G
SDX65
SDX55M
SD888 5G
SD870
WCN6750
WSA8835
WSA8830
WSA8815
WSA8810
WCN7851
WCN7850
WCN6856
WCN6855
WCN6851
WCN6850
SD865 5G
WCN3998
WCN3991
WCN3990
WCN3988
WCN3980
WCN3950
WCN3910
WCN3680B
WCN3660B
WCN3615
QCA6595AU
QSM8350
QCX315
QCS6490
QCS6125
QCS610
QCS410
QCM6490
QCM6125
QCA8337
QCA8081
QCA6696
Qualcomm215
QCA6574A
QCA6436
QCA6431
QCA6426
QCA6421
QCA6391
QCA6390
AR8035
SD678
SD778G
SD768G
SD765G
SD765
SD750G
SD720G
SD690 5G
SD480
SD439
SD429
SD 675
SA515M
SDX55
QCA6574AU
MSM8917
SD855
SD845
SD730
APQ8017
SD675
SD670
SD665
SD210
SD205

How to mitigate CVE-2021-1981

Install updates from vendor's website.


External References

Related Security Bulletins