Vulnerability Description
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Fastconnect 6800 Firmware | - |
| Qualcomm | Fastconnect 6800 | - |
| Qualcomm | Fastconnect 6900 Firmware | - |
| Qualcomm | Fastconnect 6900 | - |
| Qualcomm | Fastconnect 7800 Firmware | - |
| Qualcomm | Fastconnect 7800 | - |
| Qualcomm | Qca6391 Firmware | - |
| Qualcomm | Qca6391 | - |
| Qualcomm | Qca6426 Firmware | - |
| Qualcomm | Qca6426 | - |
| Qualcomm | Qca6436 Firmware | - |
| Qualcomm | Qca6436 | - |
| Qualcomm | Qcn9074 Firmware | - |
| Qualcomm | Qcn9074 | - |
| Qualcomm | Qcs410 Firmware | - |
| Qualcomm | Qcs410 | - |
| Qualcomm | Qcs610 Firmware | - |
| Qualcomm | Qcs610 | - |
| Qualcomm | Sd865 5G Firmware | - |
| Qualcomm | Sd865 5G | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/august-2023-bulletinPatchVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/august-2023-bulletinPatchVendor Advisory
FAQ
What is CVE-2023-28576?
CVE-2023-28576 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g....
How severe is CVE-2023-28576?
CVE-2023-28576 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28576?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Fastconnect 6800 Firmware, Qualcomm Fastconnect 6800, Qualcomm Fastconnect 6900 Firmware, Qualcomm Fastconnect 6900, Qualcomm Fastconnect 7800 Firmware.