SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-28576

This may lead to out-of-bounds read/write issues.

HIGH 7.0EPSS 0.08%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.

CVSS 3.1
7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.08% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-367
Affected
qualcomm/fastconnect 6800 firmware · qualcomm/fastconnect 6900 firmware · qualcomm/fastconnect 7800 firmware · qualcomm/qca6391 firmware · qualcomm/qca6426 firmware · qualcomm/qca6436 firmware · qualcomm/qcn9074 firmware · qualcomm/qcs410 firmware · qualcomm/qcs610 firmware · qualcomm/sd865 5g firmware · qualcomm/snapdragon 8 gen 1 firmware · qualcomm/snapdragon 865 5g firmware · qualcomm/snapdragon 865\+ 5g firmware · qualcomm/snapdragon 870 5g firmware · qualcomm/snapdragon x55 5g firmware · qualcomm/snapdragon xr2 5g firmware · qualcomm/sw5100 firmware · qualcomm/sw5100p firmware · qualcomm/sxr2130 firmware · qualcomm/wcd9341 firmware · +11 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.