SB2024050704 - Multiple vulnerabilities in Qualcomm chipsets



SB2024050704 - Multiple vulnerabilities in Qualcomm chipsets

Published: May 7, 2024

Security Bulletin ID SB2024050704
Severity
Medium
Patch available
YES
Number of vulnerabilities 18
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 17% Low 83%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 18 secuirty vulnerabilities.


1) Stack-based buffer overflow (CVE-ID: CVE-2024-21474)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in PMIC. A local application can execute arbitrary code.


2) Improper Access Control (CVE-ID: CVE-2024-23351)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Graphics Linux. A local application can execute arbitrary code.


3) Use After Free (CVE-ID: CVE-2024-21471)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Graphics Linux. A local application can execute arbitrary code.


4) Buffer over-read (CVE-ID: CVE-2024-21477)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in WLAN Firmware. A remote attacker can perform a denial of service (DoS) attack.


5) Access of Uninitialized Pointer (CVE-ID: CVE-2023-43531)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in SPS Applications. A local application can execute arbitrary code.


6) Integer overflow (CVE-ID: CVE-2023-43530)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in HLOS. A local application can read and manipulate data.


7) Reachable Assertion (CVE-ID: CVE-2023-43529)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in Data Modem. A remote attacker can perform a denial of service (DoS) attack.


8) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2023-33119)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Hypervisor. A local application can execute arbitrary code.


9) Buffer over-read (CVE-ID: CVE-2023-43528)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in Audio. A local application can read and manipulate data.


10) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2024-21475)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Video. A local application can execute arbitrary code.


11) Buffer overflow (CVE-ID: CVE-2023-43526)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.


12) Buffer overflow (CVE-ID: CVE-2023-43525)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.


13) Buffer overflow (CVE-ID: CVE-2023-43524)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.


14) Use After Free (CVE-ID: CVE-2023-43521)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in HLOS. A local privileged application can execute arbitrary code.


15) Use After Free (CVE-ID: CVE-2024-23354)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Graphics Linux. A local application can execute arbitrary code.


16) Buffer over-read (CVE-ID: CVE-2023-43527)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in Video. A local application can read and manipulate data.


17) Buffer overflow (CVE-ID: CVE-2024-21480)

The vulnerability allows a remote attacker to read and manipulate data.

The vulnerability exists due to improper input validation in Audio. A remote attacker can read and manipulate data.


18) Improper input validation (CVE-ID: CVE-2024-21476)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Secure Processor. A local application can execute arbitrary code.


Remediation

Install update from vendor's website.