Reachable Assertion in Qualcomm products - CVE-2021-30307

 

Reachable Assertion in Qualcomm products - CVE-2021-30307

Published: January 4, 2022


Vulnerability identifier: #VU59192
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30307
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of DNS response when DNS client requests with PTR, NAPTR or SRV query type within the Data Modem component. A remote attacker can send a specially crafted response to the device, trigger an assertion failure and perform a denial denial of service (DoS) attack.


Affected software

SD8885G
SM7250P
SM6375
SM6250P
SM6250
SM6225
SDXR25G
SDX65
SDX55M
SM7315
SD870
SD8655G
SD7c
SD778G
SD768G
SD765G
SD765
SD750G
WCN3980
WSA8835
WSA8830
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCN3991
WCN3990
WCN3988
SD720G
WCN3950
WCN3910
WCD9385
WCD9380
WCD9375
WCD9370
WCD9360
WCD9340
SM7325P
QCA6595AU
QCS4290
QCS410
QCS2290
QCM6490
QCM4290
QCM2290
QCA8337
QCA8081
QCA6696
QCS610
QCA6574A
QCA6564AU
QCA6436
QCA6426
QCA6391
QCA6390
CSRB31024
SA8155P
SD6905G
SD678
SD662
SD480
SD460
SD8cxGen2
SD8Gen15G
SA8195P
AR8035
SA8150P
SA8145P
SA6150P
SA6145P
SA515M
SA415M
QCX315
QCS6490
SDX55
SDX24
SD888
SD730
QCA9377
QCA6574AU
QCA6174A
SD665
SD675
SA6155P
Google Android

How to mitigate CVE-2021-30307

Install updates from vendor's website.

Google Android - addressed in versions 9 2022-01-05, 10 2022-01-05, 11 2022-01-05, 12 2022-01-05

External References

Related Security Bulletins