CVE-2023-21639

Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
qualcommaqt1000_firmware
-
qualcommfastconnect_6200_firmware
-
qualcommqca6420_firmware
-
qualcommqca6430_firmware
-
qualcommsa4150p_firmware
-
qualcommsa4155p_firmware
-
qualcommsa6155p_firmware
-
qualcommsa8155p_firmware
-
qualcommsa8195p_firmware
-
qualcommsd855_firmware
-
qualcommsnapdragon_855_firmware
-
qualcommsnapdragon_855\+\/860_firmware
-
qualcommsnapdragon_w5\+_gen_1_firmware
-
qualcommsw5100_firmware
-
qualcommsw5100p_firmware
-
qualcommwcd9341_firmware
-
qualcommwcn3980_firmware
-
qualcommwcn3988_firmware
-
qualcommwsa8810_firmware
-
qualcommwsa8815_firmware
-
qualcommwsa8830_firmware
-
qualcommwsa8835_firmware
-
𝑥
= Vulnerable software versions