Multiple Dmabuf Kernel Address UAF Vulnerability
Published Aug 8, 2023
7.8
HIGHCVSS 3.1
EPSS 0.12%
Description
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.
Affected products
-
Affected
- FastConnect 6800
- FastConnect 6900
- FastConnect 7800
- QCA6391
- QCA6426
- QCA6436
- QCN9074
- QCS410
- QCS610
- SD865 5G
- SW5100
- SW5100P
- SXR2130
- Snapdragon 8 Gen 1 Mobile Platform
- Snapdragon 865 5G Mobile Platform
- Snapdragon 865+ 5G Mobile Platform (SM8250-AB)
- Snapdragon 870 5G Mobile Platform (SM8250-AC)
- Snapdragon X55 5G Modem-RF System
- Snapdragon XR2 5G Platform
- WCD9341
- WCD9370
- WCD9380
- WCN3660B
- WCN3680B
- WCN3950
- WCN3980
- WCN3988
- WSA8810
- WSA8815
- WSA8830
- WSA8835
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Qualcomm, Inc. | Snapdragon | unaffected | Affected
|
Configuration 1
- n/a
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Running on/with
- n/a
Configuration 12
- n/a
Running on/with
- n/a
Configuration 13
- n/a
Running on/with
- n/a
Configuration 14
- n/a
Running on/with
- n/a
Configuration 15
- n/a
Running on/with
- n/a
Configuration 16
- n/a
Running on/with
- n/a
Configuration 17
- n/a
Configuration 18
- n/a
Configuration 19
- n/a
Configuration 20
- n/a
Configuration 21
- n/a
Configuration 22
- n/a
Configuration 23
- n/a
Configuration 24
- n/a
Configuration 25
- n/a
Configuration 26
- n/a
Configuration 27
- n/a
Configuration 28
- n/a
Configuration 29
- n/a
Configuration 30
- n/a
Configuration 31
- n/a
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
-
Affected
- 0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-32247 Advisory
- https://www.qualcomm.com/company/product-security/bulletins/august-2023-bulletin PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-32247 | Advisory | |
| https://www.qualcomm.com/company/product-security/bulletins/august-2023-bulletin | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data