2023-08-08
|
CVE-2023-21627
|
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
|
Aqt1000_firmware, Qca6390_firmware, Qca6391_firmware, Qca6420_firmware, Qca6426_firmware, Qca6430_firmware, Qca6436_firmware, Qca6574au_firmware, Qca6595au_firmware, Qca6696_firmware, Qcc5100_firmware, Qcs8155_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155p_firmware, Sa8195p_firmware, Sd855_firmware, Sd865_5g_firmware, Sd870_firmware, Sd888_5g_firmware, Sd_8_gen1_5g_firmware, Sda429w_firmware, Sdx55m_firmware, Sdxr2_5g_firmware, Sw5100_firmware, Sw5100p_firmware, Wcd9341_firmware, Wcd9380_firmware, Wcd9385_firmware, Wcn3610_firmware, Wcn3660b_firmware, Wcn3680b_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn3998_firmware, Wcn6850_firmware, Wcn6851_firmware, Wcn6855_firmware, Wcn6856_firmware, Wcn7850_firmware, Wcn7851_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8835_firmware
|
7.8
|
|
|
2023-08-08
|
CVE-2023-21647
|
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
|
Qca6390_firmware, Qca6391_firmware, Qca6426_firmware, Qca6436_firmware, Qca6574au_firmware, Qca6595au_firmware, Qca6696_firmware, Qcc5100_firmware, Qcn9074_firmware, Qcs410_firmware, Qcs610_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155p_firmware, Sa8195p_firmware, Sd865_5g_firmware, Sd870_firmware, Sd_8_gen1_5g_firmware, Sdx55m_firmware, Sdxr2_5g_firmware, Sw5100_firmware, Sw5100p_firmware, Wcd9341_firmware, Wcd9370_firmware, Wcd9380_firmware, Wcn3660b_firmware, Wcn3680b_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn6850_firmware, Wcn6851_firmware, Wcn6855_firmware, Wcn6856_firmware, Wcn7850_firmware, Wcn7851_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8835_firmware
|
6.5
|
|
|
2023-08-08
|
CVE-2023-21648
|
Memory corruption in RIL while trying to send apdu packet.
|
Aqt1000_firmware, Qca6391_firmware, Qca6420_firmware, Qca6430_firmware, Qca6574a_firmware, Qca6574au_firmware, Qca6595au_firmware, Qca6696_firmware, Qcc5100_firmware, Sa515m_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155p_firmware, Sa8195p_firmware, Sd855_firmware, Sda429w_firmware, Sdx55_firmware, Sw5100_firmware, Sw5100p_firmware, Wcd9341_firmware, Wcd9360_firmware, Wcn3610_firmware, Wcn3660b_firmware, Wcn3680b_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn3998_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8835_firmware
|
7.8
|
|
|
2023-08-08
|
CVE-2023-21649
|
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
|
Apq8096au_firmware, Aqt1000_firmware, Mdm9628_firmware, Mdm9650_firmware, Qca6390_firmware, Qca6391_firmware, Qca6420_firmware, Qca6421_firmware, Qca6426_firmware, Qca6430_firmware, Qca6431_firmware, Qca6436_firmware, Qca6554a_firmware, Qca6564a_firmware, Qca6564au_firmware, Qca6574_firmware, Qca6574a_firmware, Qca6574au_firmware, Qca6584au_firmware, Qca6595_firmware, Qca6595au_firmware, Qca6696_firmware, Qca8337_firmware, Qcc5100_firmware, Qcn9074_firmware, Qcs410_firmware, Qcs610_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155p_firmware, Sa8195p_firmware, Sd480_firmware, Sd695_firmware, Sd855_firmware, Sd865_5g_firmware, Sd870_firmware, Sda429w_firmware, Sdx55_firmware, Sdx55m_firmware, Sdxr2_5g_firmware, Sm4375_firmware, Sw5100_firmware, Sw5100p_firmware, Wcd9341_firmware, Wcd9370_firmware, Wcd9375_firmware, Wcd9380_firmware, Wcd9385_firmware, Wcn3610_firmware, Wcn3660b_firmware, Wcn3680b_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn3991_firmware, Wcn3998_firmware, Wcn6850_firmware, Wcn6851_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8835_firmware
|
7.8
|
|
|
2023-08-08
|
CVE-2023-21651
|
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
|
Aqt1000_firmware, Ar8031_firmware, Ar8035_firmware, Csra6620_firmware, Csra6640_firmware, Mdm9205_firmware, Qam8295p_firmware, Qca4004_firmware, Qca6174a_firmware, Qca6310_firmware, Qca6335_firmware, Qca6390_firmware, Qca6391_firmware, Qca6420_firmware, Qca6421_firmware, Qca6426_firmware, Qca6430_firmware, Qca6431_firmware, Qca6436_firmware, Qca6564a_firmware, Qca6564au_firmware, Qca6574_firmware, Qca6574a_firmware, Qca6574au_firmware, Qca6595_firmware, Qca6595au_firmware, Qca6696_firmware, Qca8081_firmware, Qca8337_firmware, Qca9377_firmware, Qca9984_firmware, Qcc5100_firmware, Qcm2290_firmware, Qcm4290_firmware, Qcm6490_firmware, Qcn6024_firmware, Qcn7606_firmware, Qcn9011_firmware, Qcn9012_firmware, Qcn9024_firmware, Qcs2290_firmware, Qcs405_firmware, Qcs4290_firmware, Qcs603_firmware, Qcs605_firmware, Qcs6490_firmware, Qcx315_firmware, Qrb5165_firmware, Qrb5165m_firmware, Qrb5165n_firmware, Qsm8250_firmware, Qsm8350_firmware, Sa515m_firmware, Sa6145p_firmware, Sa6155_firmware, Sa6155p_firmware, Sa8150p_firmware, Sa8155_firmware, Sa8155p_firmware, Sa8295p_firmware, Sa8540p_firmware, Sa9000p_firmware, Sd460_firmware, Sd480_firmware, Sd662_firmware, Sd665_firmware, Sd670_firmware, Sd675_firmware, Sd678_firmware, Sd680_firmware, Sd690_5g_firmware, Sd695_firmware, Sd750g_firmware, Sd765_firmware, Sd765g_firmware, Sd768g_firmware, Sd778g_firmware, Sd780g_firmware, Sd845_firmware, Sd850_firmware, Sd855_firmware, Sd865_5g_firmware, Sd870_firmware, Sd888_5g_firmware, Sd888_firmware, Sd_675_firmware, Sd_8_gen1_5g_firmware, Sd_8cx_firmware, Sd_8cx_gen2_firmware, Sd_8cx_gen3_firmware, Sdx24_firmware, Sdx50m_firmware, Sdx55_firmware, Sdx55m_firmware, Sdx57m_firmware, Sdx65_firmware, Sdxr2_5g_firmware, Sg4150p_firmware, Sm4125_firmware, Sm4375_firmware, Sm7250p_firmware, Sm7315_firmware, Sm7325p_firmware, Ssg2115p_firmware, Ssg2125p_firmware, Sw5100_firmware, Sw5100p_firmware, Sxr1230p_firmware, Sxr2150p_firmware, Wcd9306_firmware, Wcd9326_firmware, Wcd9335_firmware, Wcd9340_firmware, Wcd9341_firmware, Wcd9360_firmware, Wcd9370_firmware, Wcd9375_firmware, Wcd9380_firmware, Wcd9385_firmware, Wcn3910_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn3990_firmware, Wcn3991_firmware, Wcn3998_firmware, Wcn3999_firmware, Wcn6740_firmware, Wcn6750_firmware, Wcn6850_firmware, Wcn6851_firmware, Wcn6855_firmware, Wcn6856_firmware, Wcn7850_firmware, Wcn7851_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8832_firmware, Wsa8835_firmware
|
7.8
|
|
|
2023-08-08
|
CVE-2023-21650
|
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
|
Aqt1000_firmware, Csrb31024_firmware, Qam8295p_firmware, Qca6390_firmware, Qca6391_firmware, Qca6420_firmware, Qca6426_firmware, Qca6430_firmware, Qca6436_firmware, Qca6564_firmware, Qca6564au_firmware, Qca6574a_firmware, Qca6574au_firmware, Qca6595au_firmware, Qca6696_firmware, Qcc5100_firmware, Qcs410_firmware, Qcs610_firmware, Sa415m_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155p_firmware, Sa8195p_firmware, Sa8295p_firmware, Sd855_firmware, Sd865_5g_firmware, Sd870_firmware, Sda429w_firmware, Sdx55m_firmware, Sdxr2_5g_firmware, Sw5100_firmware, Sw5100p_firmware, Wcd9341_firmware, Wcd9370_firmware, Wcd9380_firmware, Wcn3610_firmware, Wcn3660b_firmware, Wcn3680b_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn3998_firmware, Wcn6850_firmware, Wcn6851_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8835_firmware
|
7.8
|
|
|
2023-08-08
|
CVE-2023-21652
|
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
|
Aqt1000_firmware, Ar8035_firmware, Csra6620_firmware, Csra6640_firmware, Qam8295p_firmware, Qca6390_firmware, Qca6391_firmware, Qca6420_firmware, Qca6421_firmware, Qca6426_firmware, Qca6430_firmware, Qca6431_firmware, Qca6436_firmware, Qca6574_firmware, Qca6574a_firmware, Qca6574au_firmware, Qca6595_firmware, Qca6595au_firmware, Qca6696_firmware, Qca8081_firmware, Qca8337_firmware, Qcc5100_firmware, Qcm2290_firmware, Qcm4290_firmware, Qcm6125_firmware, Qcm6490_firmware, Qcn6024_firmware, Qcn7606_firmware, Qcn9024_firmware, Qcs2290_firmware, Qcs405_firmware, Qcs4290_firmware, Qcs6125_firmware, Qcs6490_firmware, Qsm8350_firmware, Sa4150p_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155_firmware, Sa8155p_firmware, Sa8195p_firmware, Sa8295p_firmware, Sa8540p_firmware, Sa9000p_firmware, Sd460_firmware, Sd480_firmware, Sd662_firmware, Sd665_firmware, Sd670_firmware, Sd675_firmware, Sd678_firmware, Sd680_firmware, Sd690_5g_firmware, Sd695_firmware, Sd710_firmware, Sd720g_firmware, Sd730_firmware, Sd750g_firmware, Sd765_firmware, Sd765g_firmware, Sd768g_firmware, Sd778g_firmware, Sd780g_firmware, Sd855_firmware, Sd865_5g_firmware, Sd870_firmware, Sd888_5g_firmware, Sd888_firmware, Sd_675_firmware, Sd_8_gen1_5g_firmware, Sd_8cx_gen3_firmware, Sdx50m_firmware, Sdx55m_firmware, Sdx65_firmware, Sdxr1_firmware, Sdxr2_5g_firmware, Sg4150p_firmware, Sm4125_firmware, Sm4375_firmware, Sm6250_firmware, Sm7250p_firmware, Sm7315_firmware, Sm7325p_firmware, Ssg2115p_firmware, Ssg2125p_firmware, Sw5100_firmware, Sw5100p_firmware, Sxr1230p_firmware, Sxr2150p_firmware, Wcd9326_firmware, Wcd9335_firmware, Wcd9341_firmware, Wcd9370_firmware, Wcd9375_firmware, Wcd9380_firmware, Wcd9385_firmware, Wcn3910_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn3990_firmware, Wcn3991_firmware, Wcn3998_firmware, Wcn6740_firmware, Wcn6750_firmware, Wcn6850_firmware, Wcn6851_firmware, Wcn6855_firmware, Wcn6856_firmware, Wcn7850_firmware, Wcn7851_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8832_firmware, Wsa8835_firmware
|
7.1
|
|
|
2023-08-08
|
CVE-2023-28555
|
Transient DOS in Audio while remapping channel buffer in media codec decoding.
|
Ar8035_firmware, Mdm9628_firmware, Qam8295p_firmware, Qca6564a_firmware, Qca6564au_firmware, Qca6574_firmware, Qca6574a_firmware, Qca6574au_firmware, Qca6595au_firmware, Qca6696_firmware, Qca8081_firmware, Qca8337_firmware, Qcm4325_firmware, Qcm4490_firmware, Qcn6024_firmware, Qcn9024_firmware, Qcs4490_firmware, Sa4150p_firmware, Sa4155p_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155p_firmware, Sa8195p_firmware, Sa8295p_firmware, Sd865_5g_firmware, Sdx55_firmware, Sg4150p_firmware, Sm4350\-Ac_firmware, Sm4350_firmware, Sm4450_firmware, Sm6225\-Ad_firmware, Sm6225_firmware, Sm6375_firmware, Sm8350\-Ac_firmware, Sm8350_firmware, Sm8450_firmware, Sm8475_firmware, Snapdragon_ar2_gen_1_platform_firmware, Snapdragon_auto_5g_modem\-Rf_firmware, Snapdragon_w5\+_gen_1_wearable_platform_firmware, Snapdragon_x65_5g_modem\-Rf_system_firmware, Snapdragon_xr2_5g_platform_firmware, Ssg2115p_firmware, Ssg2125p_firmware, Sw5100_firmware, Sw5100p_firmware, Sxr1230p_firmware, Sxr2230p_firmware, Wcd9370_firmware, Wcd9375_firmware, Wcd9380_firmware, Wcd9385_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wcn3991_firmware, Wcn3998_firmware, Wcn6740_firmware, Wcn6750_firmware, Wcn685x\-1_firmware, Wcn685x\-5_firmware, Wcn785x\-1_firmware, Wcn785x\-5_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8832_firmware, Wsa8835_firmware
|
7.5
|
|
|
2023-08-08
|
CVE-2023-28575
|
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
|
205_firmware, 215_firmware, Aqt1000_firmware, C\-V2x_9150_firmware, Fastconnect_6200_firmware, Fastconnect_6800_firmware, Fastconnect_6900_firmware, Fastconnect_7800_firmware, Qam8295p_firmware, Qca6391_firmware, Qca6420_firmware, Qca6426_firmware, Qca6430_firmware, Qca6436_firmware, Qca6574au_firmware, Qca6696_firmware, Qca8337_firmware, Qcn9074_firmware, Qcs410_firmware, Qcs610_firmware, Qcs8155_firmware, Sa6145p_firmware, Sa6150p_firmware, Sa6155p_firmware, Sa8145p_firmware, Sa8150p_firmware, Sa8155p_firmware, Sa8195p_firmware, Sa8295p_firmware, Sd210_firmware, Sd212_firmware, Sd855_firmware, Sd865_5g_firmware, Sdx55_firmware, Snapdragon_855\+\/860_firmware, Snapdragon_855_firmware, Snapdragon_865\+_5g_firmware, Snapdragon_865_5g_firmware, Snapdragon_870_5g_firmware, Snapdragon_8_gen_1_firmware, Snapdragon_w5\+_gen_1_firmware, Snapdragon_wear_4100\+_firmware, Snapdragon_x55_5g_firmware, Snapdragon_xr2_5g_firmware, Sw5100_firmware, Sw5100p_firmware, Sxr2130_firmware, Wcd9341_firmware, Wcd9370_firmware, Wcd9380_firmware, Wcn3610_firmware, Wcn3660b_firmware, Wcn3680b_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8835_firmware
|
7.8
|
|
|
2023-08-08
|
CVE-2023-28576
|
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.
|
Fastconnect_6800_firmware, Fastconnect_6900_firmware, Fastconnect_7800_firmware, Qca6391_firmware, Qca6426_firmware, Qca6436_firmware, Qcn9074_firmware, Qcs410_firmware, Qcs610_firmware, Sd865_5g_firmware, Snapdragon_865\+_5g_firmware, Snapdragon_865_5g_firmware, Snapdragon_870_5g_firmware, Snapdragon_8_gen_1_firmware, Snapdragon_x55_5g_firmware, Snapdragon_xr2_5g_firmware, Sw5100_firmware, Sw5100p_firmware, Sxr2130_firmware, Wcd9341_firmware, Wcd9370_firmware, Wcd9380_firmware, Wcn3660b_firmware, Wcn3680b_firmware, Wcn3950_firmware, Wcn3980_firmware, Wcn3988_firmware, Wsa8810_firmware, Wsa8815_firmware, Wsa8830_firmware, Wsa8835_firmware
|
7.0
|
|
|