In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Qualcomm
Subscribe
|
Fastconnect 6800
Subscribe
Fastconnect 6800 Firmware
Subscribe
Fastconnect 6900
Subscribe
Fastconnect 6900 Firmware
Subscribe
Fastconnect 7800
Subscribe
Fastconnect 7800 Firmware
Subscribe
Qca6391
Subscribe
Qca6391 Firmware
Subscribe
Qca6426
Subscribe
Qca6426 Firmware
Subscribe
Qca6436
Subscribe
Qca6436 Firmware
Subscribe
Qcn9074
Subscribe
Qcn9074 Firmware
Subscribe
Qcs410
Subscribe
Qcs410 Firmware
Subscribe
Qcs610
Subscribe
Qcs610 Firmware
Subscribe
Sd865 5g
Subscribe
Sd865 5g Firmware
Subscribe
Snapdragon 865\+ 5g
Subscribe
Snapdragon 865\+ 5g Firmware
Subscribe
Snapdragon 865 5g
Subscribe
Snapdragon 865 5g Firmware
Subscribe
Snapdragon 865 5g Mobile Platform Firmware
Subscribe
Snapdragon 870 5g
Subscribe
Snapdragon 870 5g Firmware
Subscribe
Snapdragon 8 Gen 1
Subscribe
Snapdragon 8 Gen 1 Firmware
Subscribe
Snapdragon 8 Gen 1 Mobile Platform Firmware
Subscribe
Snapdragon X55 5g
Subscribe
Snapdragon X55 5g Firmware
Subscribe
Snapdragon X55 5g Modem-rf System Firmware
Subscribe
Snapdragon Xr2 5g
Subscribe
Snapdragon Xr2 5g Firmware
Subscribe
Snapdragon Xr2 5g Platform Firmware
Subscribe
Sw5100
Subscribe
Sw5100 Firmware
Subscribe
Sw5100p
Subscribe
Sw5100p Firmware
Subscribe
Sxr2130
Subscribe
Sxr2130 Firmware
Subscribe
Wcd9341
Subscribe
Wcd9341 Firmware
Subscribe
Wcd9370
Subscribe
Wcd9370 Firmware
Subscribe
Wcd9380
Subscribe
Wcd9380 Firmware
Subscribe
Wcn3660b
Subscribe
Wcn3660b Firmware
Subscribe
Wcn3680b
Subscribe
Wcn3680b Firmware
Subscribe
Wcn3950
Subscribe
Wcn3950 Firmware
Subscribe
Wcn3980
Subscribe
Wcn3980 Firmware
Subscribe
Wcn3988
Subscribe
Wcn3988 Firmware
Subscribe
Wsa8810
Subscribe
Wsa8810 Firmware
Subscribe
Wsa8815
Subscribe
Wsa8815 Firmware
Subscribe
Wsa8830
Subscribe
Wsa8830 Firmware
Subscribe
Wsa8835
Subscribe
Wsa8835 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32247 | In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qualcomm
Published:
Updated: 2024-08-02T13:43:23.051Z
Reserved: 2023-03-17T11:41:45.851Z
Link: CVE-2023-28577
Updated: 2024-07-11T20:32:05.287Z
Status : Modified
Published: 2023-08-08T10:15:14.760
Modified: 2024-11-21T07:55:34.353
Link: CVE-2023-28577
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD