CVE-2023-28576
Last modified
CVE-2023-28576 is a high-severity vulnerability rated 7/10 on the CVSS scale. The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. EPSS estimates a 0.08% chance of exploitation in the next 30 days.
Description
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Fastconnect 6800 Firmware | All versions |
| Qualcomm | Fastconnect 6900 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Qca6391 Firmware | All versions |
| Qualcomm | Qca6426 Firmware | All versions |
| Qualcomm | Qca6436 Firmware | All versions |
| Qualcomm | Qcn9074 Firmware | All versions |
| Qualcomm | Qcs410 Firmware | All versions |
| Qualcomm | Qcs610 Firmware | All versions |
| Qualcomm | Sd865 5g Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 1 Firmware | All versions |
| Qualcomm | Snapdragon 865 5g Firmware | All versions |
| Qualcomm | Snapdragon 865\+ 5g Firmware | All versions |
| Qualcomm | Snapdragon 870 5g Firmware | All versions |
| Qualcomm | Snapdragon X55 5g Firmware | All versions |
| Qualcomm | Snapdragon Xr2 5g Firmware | All versions |
| Qualcomm | Sw5100 Firmware | All versions |
| Qualcomm | Sw5100p Firmware | All versions |
| Qualcomm | Sxr2130 Firmware | All versions |
| Qualcomm | Wcd9341 Firmware | All versions |
| Qualcomm | Wcd9370 Firmware | All versions |
| Qualcomm | Wcd9380 Firmware | All versions |
| Qualcomm | Wcn3660b Firmware | All versions |
| Qualcomm | Wcn3680b Firmware | All versions |
| Qualcomm | Wcn3950 Firmware | All versions |
| Qualcomm | Wcn3980 Firmware | All versions |
| Qualcomm | Wcn3988 Firmware | All versions |
| Qualcomm | Wsa8810 Firmware | All versions |
| Qualcomm | Wsa8815 Firmware | All versions |
| Qualcomm | Wsa8830 Firmware | All versions |
| Qualcomm | Wsa8835 Firmware | All versions |
References
- https://www.qualcomm.com/company/product-security/bulletins/august-2023-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/august-2023-bulletinPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-28576?
How severe is CVE-2023-28576?
How do I fix CVE-2023-28576?
Are you affected by CVE-2023-28576?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
