Buffer overflow in Qualcomm products - CVE-2023-43556

 

Buffer overflow in Qualcomm products - CVE-2023-43556

Published: June 4, 2024


Vulnerability identifier: #VU91026
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-43556
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
AR8035
FastConnect 6700
FastConnect 6900
FastConnect 7800
Flight RB5 5G Platform
QAM8295P
QCA6391
QCA6595
QCA6696
QCA6698AQ
QCA8081
QCA8337
QCM4490
QCM5430
QCM6490
QCN6024
QCN9011
QCN9012
QCN9024
QCS4490
QCS5430
QCS6490
QCS7230
QCS8250
QRB5165M
QRB5165N
QSM8350
Qualcomm Video Collaboration VC3 Platform
Qualcomm Video Collaboration VC5 Platform
Robotics RB5 Platform
SA8295P
SDX57M
SM7315
SM7325P
Snapdragon 4 Gen 2 Mobile Platform
Snapdragon 778G 5G Mobile Platform
Snapdragon 778G+ 5G Mobile Platform (SM7325-AE)
Snapdragon 780G 5G Mobile Platform
Snapdragon 782G Mobile Platform (SM7325-AF)
Snapdragon 7c+ Gen 3 Compute
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 8+ Gen 1 Mobile Platform
Snapdragon 888 5G Mobile Platform
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
BB)
Snapdragon AR2 Gen 1 Platform
Snapdragon X65 5G Modem-RF System
Snapdragon X70 Modem-RF System
SSG2115P
SSG2125P
SXR1230P
SXR2230P
WCD9370
WCD9375
WCD9380
WCD9385
WCN3950
WCN3988
WCN6740
WSA8810
WSA8815
WSA8830
WSA8835
QCA6574AU
SA8540P
SA9000P
SD888
WSA8832
Software vendor:
Qualcomm

Description

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Hypervisor. A local application can execute arbitrary code.


Remediation

Install security update from vendor's website.

External links