#VU61844 Improper Validation of Array Index in Qualcomm Hardware solutions


Published: 2022-04-04

Vulnerability identifier: #VU61844

Vulnerability risk: Low

CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-35126

CWE-ID: CWE-129

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
QAM8295P
Mobile applications / Mobile firmware & hardware
QCA6391
Mobile applications / Mobile firmware & hardware
QCA6696
Mobile applications / Mobile firmware & hardware
QCM6490
Mobile applications / Mobile firmware & hardware
QCS6490
Mobile applications / Mobile firmware & hardware
SA8295P
Mobile applications / Mobile firmware & hardware
SD8Gen15G
Mobile applications / Mobile firmware & hardware
SD8cxGen3
Mobile applications / Mobile firmware & hardware
SD778G
Mobile applications / Mobile firmware & hardware
SD780G
Mobile applications / Mobile firmware & hardware
SD8885G
Mobile applications / Mobile firmware & hardware
SM7315
Mobile applications / Mobile firmware & hardware
SM7325P
Mobile applications / Mobile firmware & hardware
WCD9370
Mobile applications / Mobile firmware & hardware
WCD9375
Mobile applications / Mobile firmware & hardware
WCD9380
Mobile applications / Mobile firmware & hardware
WCD9385
Mobile applications / Mobile firmware & hardware
WCN6740
Mobile applications / Mobile firmware & hardware
WCN6750
Mobile applications / Mobile firmware & hardware
WCN6850
Mobile applications / Mobile firmware & hardware
WCN6851
Mobile applications / Mobile firmware & hardware
WCN6855
Mobile applications / Mobile firmware & hardware
WCN6856
Mobile applications / Mobile firmware & hardware
WSA8830
Mobile applications / Mobile firmware & hardware
WSA8835
Mobile applications / Mobile firmware & hardware
SD888
Hardware solutions / Firmware

Vendor: Qualcomm

Description

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper validation of array index within the DSP Service. A malicious application can trigger a boundary error and execute arbitrary code with elevated privileges.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

QAM8295P: All versions

QCA6391: All versions

QCA6696: All versions

QCM6490: All versions

QCS6490: All versions

SA8295P: All versions

SD8Gen15G: All versions

SD8cxGen3: All versions

SD778G: All versions

SD780G: All versions

SD888: All versions

SD8885G: All versions

SM7315: All versions

SM7325P: All versions

WCD9370: All versions

WCD9375: All versions

WCD9380: All versions

WCD9385: All versions

WCN6740: All versions

WCN6750: All versions

WCN6850: All versions

WCN6851: All versions

WCN6855: All versions

WCN6856: All versions

WSA8830: All versions

WSA8835: All versions


External links
http://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletin


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability