NULL pointer dereference in Qualcomm products - CVE-2021-35087

 

NULL pointer dereference in Qualcomm products - CVE-2021-35087

Published: May 12, 2022 / Updated: May 12, 2022


Vulnerability identifier: #VU63110
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35087
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of system information message to be processed in Modem component. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

WCN6740
SDX65
SM7250P
WCD9341
WCD9370
WCD9375
WCD9380
WCD9385
WCN3988
WCN3991
WCN3998
SDX55M
WCN6750
WCN6850
WCN6851
WCN6855
WCN6856
WSA8810
WSA8815
WSA8830
WSA8835
SD695
QCA6390
QCA6391
QCA8081
QCA8337
QCM6490
QCS6490
SD 8 Gen1 5G
SD480
SD690 5G
AR8035
SD765
SD765G
SD768G
SD778G
SD780G
SD865 5G
SD870
SD888 5G
SDX55

How to mitigate CVE-2021-35087

Install updates from vendor's website.


External References

Related Security Bulletins