Impact
An integer underflow flaw in the WLAN host triggers when it processes wireless channel switch messages that contain improperly formatted length fields. The underflow makes the implementation read past the intended bounds, potentially exposing parts of device memory that can contain confidential data. This vulnerability is classified as CWE-191 and may lead to the disclosure of sensitive information such as authentication credentials or user data.
Affected Systems
Qualcomm, Inc. Snapdragon wireless chipsets are affected. Any device that incorporates a Snapdragon firmware stack capable of handling channel switch control frames may be vulnerable, as the advisory does not provide specific patched releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data are not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a malicious channel switch packet transmitted over a wireless channel, which is feasible for an attacker with proximity or who can access the same network. Successful exploitation would allow an attacker to extract data from the device’s memory.
OpenCVE Enrichment