Description
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.
Published: 2023-08-08
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-32246 The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.
History

No history.

Subscriptions

Qualcomm Fastconnect 6800 Fastconnect 6800 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Qca6391 Qca6391 Firmware Qca6426 Qca6426 Firmware Qca6436 Qca6436 Firmware Qcn9074 Qcn9074 Firmware Qcs410 Qcs410 Firmware Qcs610 Qcs610 Firmware Sd865 5g Sd865 5g Firmware Snapdragon 865\+ 5g Snapdragon 865\+ 5g Firmware Snapdragon 865 5g Snapdragon 865 5g Firmware Snapdragon 870 5g Snapdragon 870 5g Firmware Snapdragon 8 Gen 1 Snapdragon 8 Gen 1 Firmware Snapdragon X55 5g Snapdragon X55 5g Firmware Snapdragon Xr2 5g Snapdragon Xr2 5g Firmware Sw5100 Sw5100 Firmware Sw5100p Sw5100p Firmware Sxr2130 Sxr2130 Firmware Wcd9341 Wcd9341 Firmware Wcd9370 Wcd9370 Firmware Wcd9380 Wcd9380 Firmware Wcn3660b Wcn3660b Firmware Wcn3680b Wcn3680b Firmware Wcn3950 Wcn3950 Firmware Wcn3980 Wcn3980 Firmware Wcn3988 Wcn3988 Firmware Wsa8810 Wsa8810 Firmware Wsa8815 Wsa8815 Firmware Wsa8830 Wsa8830 Firmware Wsa8835 Wsa8835 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-02T13:43:22.705Z

Reserved: 2023-03-17T11:41:45.850Z

Link: CVE-2023-28576

cve-icon Vulnrichment

Updated: 2024-07-08T17:05:06.582Z

cve-icon NVD

Status : Modified

Published: 2023-08-08T10:15:14.640

Modified: 2024-11-21T07:55:34.137

Link: CVE-2023-28576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses