漏洞信息详情
多款Qualcomm产品信息泄露漏洞
漏洞简介
Qualcomm QCA6574AU和SDX55都是美国高通(Qualcomm)公司的产品。QCA6574AU是一款中央处理器(CPU)产品。SDX55是一款调制解调器。
多款Qualcomm产品存在信息泄露漏洞,该漏洞源于在将信息复制回用户缓冲区时对内核缓冲区地址的不正确验证可能导致内核内存信息暴露给用户空间。以下产品及版本受到影响:AQT1000, AR8031, AR8035, CSRA6620, CSRA6640, FSM10055, FSM10056, MDM9150, QCA6391, QCA6420, QCA6430, QCA6574, QCA6574A, QCA6574AU, QCA6584AU, QCA6595, QCA6595AU, QCA6696, QCA8337, QCM6125, QCS405, QCS410, QCS610, QCS6125, SA6145P, SA6150P, SA6155, SA6155P, SA8145P, SA8150P, SA8155, SA8155P, SA8195P, SD 675, SD 8C, SD 8CX, SD665, SD675, SD678, SD720G, SD855, SDA429W, SDX55, SDX55M, SM6250, WCD9335, WCD9340, WCD9341, WCD9370, WCD9375, WCD9380, WCN3610, WCN3620, WCN3660B, WCN3950, WCN3980, WCN3988, WCN3991, WCN3998, WCN3999, WSA8810, WSA8815。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.qualcomm.com/company/product-security/bulletins/october-2021-bulletin。
参考网址
来源:CONFIRM
链接:https://www.qualcomm.com/company/product-security/bulletins/october-2021-bulletin
来源:device.harmonyos.com
链接:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-wearables-202111-0000001172568432
来源:www.qualcomm.com
链接:https://www.qualcomm.com/company/product-security/bulletins/october-2021-bulletin
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Google-Android-Pixel-multiple-vulnerabilities-of-October-2021-36587
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-1969
受影响实体
暂无
补丁
- 多款Qualcomm产品信息泄露漏洞的修复措施<!--2021-10-4-->
还没有评论,来说两句吧...