#VU61874 Buffer overflow in Qualcomm Hardware solutions


Published: 2022-04-05

Vulnerability identifier: #VU61874

Vulnerability risk: Low

CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-35129

CWE-ID: CWE-119

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
AR8035
Mobile applications / Mobile firmware & hardware
IPQ5010
Mobile applications / Mobile firmware & hardware
IPQ5018
Mobile applications / Mobile firmware & hardware
IPQ5028
Mobile applications / Mobile firmware & hardware
QCA2062
Mobile applications / Mobile firmware & hardware
QCA2064
Mobile applications / Mobile firmware & hardware
QCA2065
Mobile applications / Mobile firmware & hardware
QCA2066
Mobile applications / Mobile firmware & hardware
QCA6391
Mobile applications / Mobile firmware & hardware
QCA8081
Mobile applications / Mobile firmware & hardware
QCA8337
Mobile applications / Mobile firmware & hardware
QCC710
Mobile applications / Mobile firmware & hardware
QCM6490
Mobile applications / Mobile firmware & hardware
QCN6023
Mobile applications / Mobile firmware & hardware
QCN6024
Mobile applications / Mobile firmware & hardware
QCN6100
Mobile applications / Mobile firmware & hardware
QCN6102
Mobile applications / Mobile firmware & hardware
QCN6112
Mobile applications / Mobile firmware & hardware
QCN6122
Mobile applications / Mobile firmware & hardware
QCN9000
Mobile applications / Mobile firmware & hardware
QCN9012
Mobile applications / Mobile firmware & hardware
QCN9022
Mobile applications / Mobile firmware & hardware
QCN9024
Mobile applications / Mobile firmware & hardware
QCN9070
Mobile applications / Mobile firmware & hardware
QCN9072
Mobile applications / Mobile firmware & hardware
QCN9074
Mobile applications / Mobile firmware & hardware
QCN9100
Mobile applications / Mobile firmware & hardware
QCS6490
Mobile applications / Mobile firmware & hardware
SD8Gen15G
Mobile applications / Mobile firmware & hardware
SD8cxGen3
Mobile applications / Mobile firmware & hardware
SD8885G
Mobile applications / Mobile firmware & hardware
SDX65
Mobile applications / Mobile firmware & hardware
WCD9370
Mobile applications / Mobile firmware & hardware
WCD9375
Mobile applications / Mobile firmware & hardware
WCD9380
Mobile applications / Mobile firmware & hardware
WCD9385
Mobile applications / Mobile firmware & hardware
WCN6750
Mobile applications / Mobile firmware & hardware
WCN6850
Mobile applications / Mobile firmware & hardware
WCN6851
Mobile applications / Mobile firmware & hardware
WCN6855
Mobile applications / Mobile firmware & hardware
WCN6856
Mobile applications / Mobile firmware & hardware
WSA8830
Mobile applications / Mobile firmware & hardware
WSA8835
Mobile applications / Mobile firmware & hardware
QCN6132
Hardware solutions / Firmware
SD888
Hardware solutions / Firmware

Vendor: Qualcomm

Description

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error within the BT Controller. A local application can trigger memory corruption and escalate privileges on the system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

AR8035: All versions

IPQ5010: All versions

IPQ5018: All versions

IPQ5028: All versions

QCA2062: All versions

QCA2064: All versions

QCA2065: All versions

QCA2066: All versions

QCA6391: All versions

QCA8081: All versions

QCA8337: All versions

QCC710: All versions

QCM6490: All versions

QCN6023: All versions

QCN6024: All versions

QCN6100: All versions

QCN6102: All versions

QCN6112: All versions

QCN6122: All versions

QCN6132: All versions

QCN9000: All versions

QCN9012: All versions

QCN9022: All versions

QCN9024: All versions

QCN9070: All versions

QCN9072: All versions

QCN9074: All versions

QCN9100: All versions

QCS6490: All versions

SD8Gen15G: All versions

SD8cxGen3: All versions

SD888: All versions

SD8885G: All versions

SDX65: All versions

WCD9370: All versions

WCD9375: All versions

WCD9380: All versions

WCD9385: All versions

WCN6750: All versions

WCN6850: All versions

WCN6851: All versions

WCN6855: All versions

WCN6856: All versions

WSA8830: All versions

WSA8835: All versions


External links
http://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletin


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability