CVE-2023-21639

Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:qualcomm:aqt1000:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6420:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6430:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:sa4150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa4150p:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:sa4155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa4155p:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155p:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155p:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8195p:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:sd855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd855:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_855:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_855\+\/860_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_855\+\/860:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_w5\+_gen_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_w5\+_gen_1:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:qualcomm:sw5100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:qualcomm:sw5100p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100p:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9341:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3988:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*

History

12 Apr 2024, 17:16

Type Values Removed Values Added
CWE CWE-120

11 Jul 2023, 13:30

Type Values Removed Values Added
First Time Qualcomm qca6430 Firmware
Qualcomm sa8195p Firmware
Qualcomm sw5100p Firmware
Qualcomm sd855
Qualcomm sw5100p
Qualcomm sa6155p
Qualcomm wsa8835 Firmware
Qualcomm qca6420 Firmware
Qualcomm sa6155p Firmware
Qualcomm wsa8835
Qualcomm sa4155p
Qualcomm wsa8810
Qualcomm aqt1000 Firmware
Qualcomm sw5100
Qualcomm wsa8815
Qualcomm sa4150p
Qualcomm wcn3980 Firmware
Qualcomm sa8155p
Qualcomm wcd9341
Qualcomm qca6420
Qualcomm wsa8830 Firmware
Qualcomm fastconnect 6200 Firmware
Qualcomm aqt1000
Qualcomm snapdragon 855 Firmware
Qualcomm wsa8815 Firmware
Qualcomm wsa8810 Firmware
Qualcomm
Qualcomm wcn3988
Qualcomm sd855 Firmware
Qualcomm sa8195p
Qualcomm fastconnect 6200
Qualcomm snapdragon 855\+\/860 Firmware
Qualcomm wcn3988 Firmware
Qualcomm snapdragon 855
Qualcomm snapdragon W5\+ Gen 1
Qualcomm wsa8830
Qualcomm sa4155p Firmware
Qualcomm sa8155p Firmware
Qualcomm snapdragon W5\+ Gen 1 Firmware
Qualcomm sa4150p Firmware
Qualcomm snapdragon 855\+\/860
Qualcomm sw5100 Firmware
Qualcomm wcn3980
Qualcomm wcd9341 Firmware
Qualcomm qca6430
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://www.qualcomm.com/company/product-security/bulletins/july-2023-bulletin - (MISC) https://www.qualcomm.com/company/product-security/bulletins/july-2023-bulletin - Vendor Advisory
CPE cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd855:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa4150p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:aqt1000:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6200:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_w5\+_gen_1:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw5100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw5100p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6420:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_855\+\/860:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa4150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3988:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6430:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_855\+\/860_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8195p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa4155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_w5\+_gen_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa4155p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_855:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9341:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*

04 Jul 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-04 05:15

Updated : 2024-04-12 17:16


NVD link : CVE-2023-21639

Mitre link : CVE-2023-21639

CVE.ORG link : CVE-2023-21639


JSON object : View

Products Affected

qualcomm

  • sa8195p
  • qca6420_firmware
  • sa8155p
  • wsa8830_firmware
  • wsa8830
  • wsa8835_firmware
  • sa4155p
  • wsa8815
  • snapdragon_855\+\/860_firmware
  • wsa8815_firmware
  • wsa8810
  • sa6155p_firmware
  • sd855_firmware
  • snapdragon_w5\+_gen_1
  • sa4150p_firmware
  • wcn3980_firmware
  • sa8155p_firmware
  • snapdragon_855_firmware
  • sw5100p
  • fastconnect_6200_firmware
  • sw5100
  • sa6155p
  • wsa8835
  • sa4155p_firmware
  • qca6430
  • wcd9341_firmware
  • aqt1000_firmware
  • sw5100p_firmware
  • snapdragon_w5\+_gen_1_firmware
  • aqt1000
  • qca6420
  • snapdragon_855
  • sa8195p_firmware
  • sa4150p
  • wcn3980
  • wcn3988
  • qca6430_firmware
  • sw5100_firmware
  • sd855
  • wcn3988_firmware
  • snapdragon_855\+\/860
  • wsa8810_firmware
  • wcd9341
  • fastconnect_6200
CWE
CWE-787

Out-of-bounds Write

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')