Buffer overflow in Qualcomm products - CVE-2021-30336

 

Buffer overflow in Qualcomm products - CVE-2021-30336

Published: December 7, 2021


Vulnerability identifier: #VU58581
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30336
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in DSP Services. A local user can trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

SDXR1
SM8450P
SM8450
SM7325P
SM7315
SM7250P
SM6375
SM6250
SM6225
WCD9370
SDX55M
SDA429W
SD888 5G
SD870
SD865 5G
SD780G
SD778G
WCN3991
WSA8835
WSA8830
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCN6740
SD768G
WCN3988
WCN3950
WCN3910
WCN3660B
WCN3610
WCD9385
WCD9380
WCD9375
QCM6490
SA6155
SA6150P
SA6145P
Qualcomm215
QCS6490
QCS4290
QCS2290
SA8145P
QCM4290
QCM2290
QCA6696
QCA6595AU
QCA6574A
QCA6574
QCA6391
SD765G
SD765
SD750G
SD720G
SD690 5G
SD678
QCA6390
SD662
SD480
SD460
SD 675
SA8195P
SA8155P
SA8155
SA8150P
SD888
SA6155P
QCA6574AU
SD665
SD730
SD675

How to mitigate CVE-2021-30336

Install updates from vendor's website.


External References

Related Security Bulletins