Buffer overflow in Qualcomm products - CVE-2021-30327

 

Buffer overflow in Qualcomm products - CVE-2021-30327

Published: April 4, 2022


Vulnerability identifier: #VU61832
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30327
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the EDL Sahara protocol implementation. An attacker with physical access to device can trigger memory corruption and execute arbitrary code on the target system.


Affected software

SDA845
SDM845
SDM710
SDM670
SDM660
SDA660
SC8180X
SXR2130
SM8250
SM8150
SM7150
SM6150
SDX55
SDX24
QCN7605
QCS405
MSM8998
APQ8098
SDM850
SDM830
SDM712
SDM658
SDM640
SDPX55M
SDA830
SDA670
SDA658
SC8180XP
SC7180P
SC7180
SA8195P
SM7125
SXR2130P
SM8150P
SM7250P
SM7250
SM7150P
SA8155P
SM6250P
SM6250
SM6150P
SM6125
SM4250
SDX24M
QCA6595
QCS404
QCS403
QCS402
QCS401
QCN7606W
QCN7606
QCN7605W
QCA6595AU
MSM8997
MDM9205
IPQ6028
IPQ6018
IPQ6010
IPQ6005
IPQ6000
SA6115
SA8155
SA8150P
SA615xP
SA615x
SA6145P
SA6145
SA6125P
SA6125
SA6115P
APQ8097
SA515M
SA4250P
SA415M
SA4155P
SA4150P
SA2150P
SA2145P
QCS407

How to mitigate CVE-2021-30327

Install updates from vendor's website.


External References

Related Security Bulletins