漏洞信息详情
多款Qualcomm产品缓冲区错误漏洞
漏洞简介
Qualcomm MSM8996AU等都是美国高通(Qualcomm)公司的产品。MSM8996AU是一款中央处理器(CPU)产品。QCA6574AU是一款中央处理器(CPU)产品。SDX24是一款调制解调器。
Qualcomm 存在安全漏洞,该漏洞源于将 TLV 复制到本地堆栈变量时由于 TLV 长度检查不当可能导致堆栈溢出。以下产品及版本受到影响:APQ8009, APQ8053, APQ8096AU, AQT1000, AR8031, AR8035, CSR8811, CSRA6620, CSRA6640, CSRB31024, IPQ5010, IPQ5018, IPQ5028, IPQ6000, IPQ6005, IPQ6010, IPQ6018, IPQ6028, IPQ8070, IPQ8070A, IPQ8071, IPQ8071A, IPQ8072, IPQ8072A, IPQ8074, IPQ8074A, IPQ8076, IPQ8076A, IPQ8078, IPQ8078A, IPQ8173, IPQ8174, MSM8996AU, PMP8074, QCA1023, QCA1062, QCA1064, QCA10901, QCA2062, QCA2064, QCA2065, QCA2066, QCA4010, QCA4020, QCA4024, QCA6174A, QCA6310, QCA6335, QCA6390, QCA6391, QCA6420, QCA6421, QCA6426, QCA6428, QCA6430, QCA6431, QCA6436, QCA6438, QCA6564AU, QCA6574, QCA6574A, QCA6574AU, QCA6584AU, QCA6595AU, QCA6694, QCA6696, QCA8072, QCA8075, QCA8081, QCA9369, QCA9377, QCA9379, QCA9888, QCA9889, QCA9984, QCM2290, QCM4290, QCM6125, QCM6490, QCN5021, QCN5022, QCN5024, QCN5052, QCN5054, QCN5064, QCN5121, QCN5122, QCN5124, QCN5152, QCN5154, QCN5164, QCN5550, QCN6023, QCN6024, QCN6122, QCN7605, QCN7606, QCN9000, QCN9022, QCN9024, QCN9070, QCN9072, QCN9074, QCN9100, QCS2290, QCS405, QCS410, QCS4290, QCS605, QCS610, QCS6125, QCS6490, QRB5165, QSM8350, SA8155, SA8155P, SC8180X+SDX55, SC8280XP, SD 675, SD 8C, SD 8CX, SD210, SD460, SD480, SD660, SD662, SD665, SD670, SD675, SD678, SD690 5G, SD710, SD720G, SD730, SD750G, SD765, SD765G, SD768G, SD778G, SD780G, SD7c, SD820, SD845, SD850, SD855, SD865 5G, SD870, SD888, SD888 5G, SDM830, SDX20, SDX20M, SDX24, SDX50M, SDX55, SDX55M, SDXR1, SDXR2 5G, SM4125, SM6250, SM6250P, SM7250, SM7325, WCD9326, WCD9335, WCD9340, WCD9341, WCD9360, WCD9370, WCD9371, WCD9375, WCD9380, WCD9385, WCN3610, WCN3615, WCN3660B, WCN3680B, WCN3910, WCN3950, WCN3980, WCN3988, WCN3990, WCN3991, WCN3998, WCN3999, WCN6740, WCN6750, WCN6850, WCN6851, WCN6855, WCN6856, WHS9410, WSA8810, WSA8815, WSA8830, WSA8835。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.qualcomm.com/company/product-security/bulletins/october-2021-bulletin。
参考网址
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-30288
来源:device.harmonyos.com
链接:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-wearables-202111-0000001172568432
来源:www.qualcomm.com
链接:https://www.qualcomm.com/company/product-security/bulletins/october-2021-bulletin
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Google-Android-Pixel-multiple-vulnerabilities-of-October-2021-36587
来源:source.android.com
链接:https://source.android.com/security/bulletin/2021-10-01
受影响实体
暂无
补丁
- 多款Qualcomm产品缓冲区错误漏洞的修复措施<!--2021-10-4-->
还没有评论,来说两句吧...