Buffer over-read in Qualcomm products - CVE-2024-21457

 

Buffer over-read in Qualcomm products - CVE-2024-21457

Published: July 1, 2024


Vulnerability identifier: #VU93534
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21457
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read memory contents or crash the system.

The vulnerability exists due to improper input validation in WLAN Host Communication. A remote attacker can read memory contents or crash the system.


Affected software

QCN5124
QCN6422
QCN6412
QCN6402
QCN6274
QCN6224
QCN6122
QCN6112
QCN6024
QCN6023
QCN5164
QCN5154
QCN5152
QCN6432
QCN5122
QCN5052
QCN5024
QCN5022
QCF8001
QCF8000
QCC710
QCC2076
QCC2073
QCA9889
QCA9888
QCA8386
QCA8337
WCD9340
SRV1M
SRV1H
Snapdragon X75 5G Modem-RF System
Snapdragon X72 5G Modem-RF System
Snapdragon X65 5G Modem-RF System
Snapdragon Auto 5G Modem-RF Gen 2
SDX65M
SA8775P
SA8770P
SA8650P
QCA8085
SA8255P
SA7775P
SA7255P
QFW7124
QFW7114
QCN9274
QCN9100
QCN9074
QCN9072
QCN9070
QCN9024
QCN9022
QCN9000
IPQ5332
IPQ8173
IPQ8078A
IPQ8078
IPQ8076A
IPQ8076
IPQ8074A
IPQ8072A
IPQ8071A
IPQ8070A
IPQ6028
IPQ6018
IPQ6010
IPQ6000
IPQ8174
IPQ5312
IPQ5302
IPQ5300
IPQ5028
IPQ5010
Immersive Home 326 Platform
Immersive Home 3210 Platform
Immersive Home 318 Platform
Immersive Home 316 Platform
Immersive Home 216 Platform
Immersive Home 214 Platform
FastConnect 7800
CSR8811
QCA6564AU
QCA8084
QCA8082
QCA8081
QCA8075
QCA6698AQ
QCA6696
QCA6678AQ
QCA6595AU
QCA6595
QCA6584AU
QCA6574A
QCA6574
AR8035
QCA6554A
QCA4024
QCA0000
QAMSRV1M
QAMSRV1H
QAM8775P
QAM8650P
QAM8255P
IPQ9574
IPQ9570
IPQ9554
IPQ9008
Pixel
QCN6132
SA8620P
SDX55
SA9000P
QCA6574AU

How to mitigate CVE-2024-21457

Install security update from vendor's website.

Pixel - update to 2024-07-05

External References

Related Security Bulletins