Description
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.
Published: 2023-08-08
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-32247 In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.
History

No history.

Subscriptions

Qualcomm Fastconnect 6800 Fastconnect 6800 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Qca6391 Qca6391 Firmware Qca6426 Qca6426 Firmware Qca6436 Qca6436 Firmware Qcn9074 Qcn9074 Firmware Qcs410 Qcs410 Firmware Qcs610 Qcs610 Firmware Sd865 5g Sd865 5g Firmware Snapdragon 865\+ 5g Snapdragon 865\+ 5g Firmware Snapdragon 865 5g Snapdragon 865 5g Firmware Snapdragon 865 5g Mobile Platform Firmware Snapdragon 870 5g Snapdragon 870 5g Firmware Snapdragon 8 Gen 1 Snapdragon 8 Gen 1 Firmware Snapdragon 8 Gen 1 Mobile Platform Firmware Snapdragon X55 5g Snapdragon X55 5g Firmware Snapdragon X55 5g Modem-rf System Firmware Snapdragon Xr2 5g Snapdragon Xr2 5g Firmware Snapdragon Xr2 5g Platform Firmware Sw5100 Sw5100 Firmware Sw5100p Sw5100p Firmware Sxr2130 Sxr2130 Firmware Wcd9341 Wcd9341 Firmware Wcd9370 Wcd9370 Firmware Wcd9380 Wcd9380 Firmware Wcn3660b Wcn3660b Firmware Wcn3680b Wcn3680b Firmware Wcn3950 Wcn3950 Firmware Wcn3980 Wcn3980 Firmware Wcn3988 Wcn3988 Firmware Wsa8810 Wsa8810 Firmware Wsa8815 Wsa8815 Firmware Wsa8830 Wsa8830 Firmware Wsa8835 Wsa8835 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-02T13:43:23.051Z

Reserved: 2023-03-17T11:41:45.851Z

Link: CVE-2023-28577

cve-icon Vulnrichment

Updated: 2024-07-11T20:32:05.287Z

cve-icon NVD

Status : Modified

Published: 2023-08-08T10:15:14.760

Modified: 2024-11-21T07:55:34.353

Link: CVE-2023-28577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses