SB2025010632 - Multiple vulnerabilities in Qualcomm chipsets



SB2025010632 - Multiple vulnerabilities in Qualcomm chipsets

Published: January 6, 2025

Security Bulletin ID SB2025010632
Severity
Medium
Patch available
YES
Number of vulnerabilities 19
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 5% Low 95%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 19 secuirty vulnerabilities.


1) Stack-based buffer overflow (CVE-ID: CVE-2024-45542)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


2) Buffer over-read (CVE-ID: CVE-2024-45558)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in WLAN Host Cmn. A remote attacker can perform a denial of service (DoS) attack.


3) Buffer overflow (CVE-ID: CVE-2024-21464)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Data Network Stack & Connectivity. A local application can execute arbitrary code.


4) Buffer over-read (CVE-ID: CVE-2024-45559)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in Automotive OS Platform QNX. A local application can perform a denial of service (DoS) attack.


5) Improper Validation of Array Index (CVE-ID: CVE-2024-45550)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in DSP Services. A local application can execute arbitrary code.


6) Buffer over-read (CVE-ID: CVE-2024-45548)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


7) Buffer overflow (CVE-ID: CVE-2024-45547)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


8) Buffer over-read (CVE-ID: CVE-2024-45546)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


9) Buffer overflow (CVE-ID: CVE-2024-45541)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


10) Use After Free (CVE-ID: CVE-2024-45553)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in DSP Services. A local application can execute arbitrary code.


11) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2024-43064)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Automotive OS Platform. A local privileged application can execute arbitrary code.


12) Buffer over-read (CVE-ID: CVE-2024-43063)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in Automotive Autonomy. A local application can read and manipulate data.


13) Buffer over-read (CVE-ID: CVE-2024-23366)

The vulnerability allows a local application to read, manipulate or delete data.

The vulnerability exists due to improper input validation in Automotive Autonomy. A local application can read, manipulate or delete data.


14) Buffer over-read (CVE-ID: CVE-2024-33067)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in Audio. A local application can read and manipulate data.


15) Use After Free (CVE-ID: CVE-2024-33059)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Computer Vision. A local privileged application can execute arbitrary code.


16) Buffer over-read (CVE-ID: CVE-2024-33061)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in DSP Service. A local application can read and manipulate data.


17) Use After Free (CVE-ID: CVE-2024-33055)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Computer Vision. A local privileged application can execute arbitrary code.


18) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2024-33041)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Computer Vision. A local privileged application can execute arbitrary code.


19) Out-of-bounds write (CVE-ID: CVE-2024-45555)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Automotive OS Platform QNX. A local application can execute arbitrary code.


Remediation

Install update from vendor's website.