Buffer overflow in Qualcomm products - CVE-2021-35123

 

Buffer overflow in Qualcomm products - CVE-2021-35123

Published: April 5, 2022


Vulnerability identifier: #VU61879
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35123
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary within the Bluetooth HOST component when processing GATT multi notifications. An attacker with physical access to device can send specially crafted packets to the device, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

WCD9370
WSA8835
WSA8830
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCN6740
WCN3998
WCN3991
WCN3988
WCN3980
WCD9385
WCD9380
WCD9375
AQT1000
WCD9335
SM7325P
SM6375
SDX55M
SD8885G
SD870
SD8655G
SD780G
SD778G
SD660
SD480
SD8Gen15G
QCA6391
QCA6390
SD855
Google Android

How to mitigate CVE-2021-35123

Install updates from vendor's website.

Google Android - addressed in versions 10 2022-04-05, 11 2022-04-05, 12L 2022-04-05, 12 2022-04-05

External References

Related Security Bulletins