Use-after-free in Qualcomm products - CVE-2021-30263

 

Use-after-free in Qualcomm products - CVE-2021-30263

Published: November 3, 2021


Vulnerability identifier: #VU57908
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30263
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to lack of synchronization mechanism when On-Device Logging node open twice concurrently. A local administrator can trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

SD 8CX
WSA8815
WSA8810
WCN3999
WCN3998
WCN3980
WCN3950
WCD9370
WCD9341
WCD9340
WCD9335
SDX55M
AQT1000
SD 8C
QCS6125
QCM6125
QCA8337
QCA6430
QCA6420
QCA6391
CSRA6640
CSRA6620
AR8035
AR8031
SDX55
SD855
QCS405

How to mitigate CVE-2021-30263

Install updates from vendor's website.


External References

Related Security Bulletins