An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'
History

Tue, 26 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm mdm9206 Firmware
Qualcomm mdm9607 Firmware
Qualcomm mdm9640 Firmware
Qualcomm mdm9650 Firmware
Qualcomm msm8909w Firmware
Qualcomm sd 425 Firmware
Qualcomm sd 430 Firmware
Qualcomm sd 450 Firmware
Qualcomm sd 617 Firmware
Qualcomm sd 625 Firmware
Qualcomm sd 810 Firmware
Qualcomm sd 820 Firmware
Qualcomm sd 820a Firmware
Qualcomm sd 835 Firmware
Qualcomm sd 845 Firmware
CPEs cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_425_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_430_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_450_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_617_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_625_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_820a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm
Qualcomm mdm9206 Firmware
Qualcomm mdm9607 Firmware
Qualcomm mdm9640 Firmware
Qualcomm mdm9650 Firmware
Qualcomm msm8909w Firmware
Qualcomm sd 425 Firmware
Qualcomm sd 430 Firmware
Qualcomm sd 450 Firmware
Qualcomm sd 617 Firmware
Qualcomm sd 625 Firmware
Qualcomm sd 810 Firmware
Qualcomm sd 820 Firmware
Qualcomm sd 820a Firmware
Qualcomm sd 835 Firmware
Qualcomm sd 845 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
Description An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'
Title Buffer Over-read in IPA
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published: 2024-11-26T13:56:25.527Z

Updated: 2024-11-26T15:00:48.248Z

Reserved: 2018-01-19T00:00:00.000Z

Link: CVE-2018-5852

cve-icon Vulnrichment

Updated: 2024-11-26T14:51:46.344Z

cve-icon NVD

Status : Received

Published: 2024-11-26T14:15:17.970

Modified: 2024-11-26T14:15:17.970

Link: CVE-2018-5852

cve-icon Redhat

No data.