SB2024050704 - Multiple vulnerabilities in Qualcomm chipsets
Published: May 7, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 18 secuirty vulnerabilities.
1) Stack-based buffer overflow (CVE-ID: CVE-2024-21474)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in PMIC. A local application can execute arbitrary code.
2) Improper Access Control (CVE-ID: CVE-2024-23351)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Graphics Linux. A local application can execute arbitrary code.
3) Use After Free (CVE-ID: CVE-2024-21471)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Graphics Linux. A local application can execute arbitrary code.
4) Buffer over-read (CVE-ID: CVE-2024-21477)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation in WLAN Firmware. A remote attacker can perform a denial of service (DoS) attack.
5) Access of Uninitialized Pointer (CVE-ID: CVE-2023-43531)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in SPS Applications. A local application can execute arbitrary code.
6) Integer overflow (CVE-ID: CVE-2023-43530)
The vulnerability allows a local application to read and manipulate data.
The vulnerability exists due to improper input validation in HLOS. A local application can read and manipulate data.
7) Reachable Assertion (CVE-ID: CVE-2023-43529)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation in Data Modem. A remote attacker can perform a denial of service (DoS) attack.
8) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2023-33119)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Hypervisor. A local application can execute arbitrary code.
9) Buffer over-read (CVE-ID: CVE-2023-43528)
The vulnerability allows a local application to read and manipulate data.
The vulnerability exists due to improper input validation in Audio. A local application can read and manipulate data.
10) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2024-21475)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Video. A local application can execute arbitrary code.
11) Buffer overflow (CVE-ID: CVE-2023-43526)
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.
12) Buffer overflow (CVE-ID: CVE-2023-43525)
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.
13) Buffer overflow (CVE-ID: CVE-2023-43524)
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.
14) Use After Free (CVE-ID: CVE-2023-43521)
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in HLOS. A local privileged application can execute arbitrary code.
15) Use After Free (CVE-ID: CVE-2024-23354)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Graphics Linux. A local application can execute arbitrary code.
16) Buffer over-read (CVE-ID: CVE-2023-43527)
The vulnerability allows a local application to read and manipulate data.
The vulnerability exists due to improper input validation in Video. A local application can read and manipulate data.
17) Buffer overflow (CVE-ID: CVE-2024-21480)
The vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to improper input validation in Audio. A remote attacker can read and manipulate data.
18) Improper input validation (CVE-ID: CVE-2024-21476)
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Secure Processor. A local application can execute arbitrary code.
Remediation
Install update from vendor's website.