Improper Validation of Array Index in Qualcomm products - CVE-2021-35126
Published: April 4, 2022
Vulnerability identifier: #VU61844
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35126
CWE-ID: CWE-129
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper validation of array index within the DSP Service. A malicious application can trigger a boundary error and execute arbitrary code with elevated privileges.
Affected software
SM7325P
WSA8835
WSA8830
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCN6740
WCD9385
WCD9380
WCD9375
WCD9370
QAM8295P
SM7315
SD8885G
SD780G
SD778G
SD8cxGen3
SD8Gen15G
SA8295P
QCS6490
QCM6490
QCA6696
QCA6391
SD888
WSA8835
WSA8830
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCN6740
WCD9385
WCD9380
WCD9375
WCD9370
QAM8295P
SM7315
SD8885G
SD780G
SD778G
SD8cxGen3
SD8Gen15G
SA8295P
QCS6490
QCM6490
QCA6696
QCA6391
SD888
How to mitigate CVE-2021-35126
Install updates from vendor's website.