ZeroHour

CVE-2023-28577

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
Description

In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.

Vendors
qualcomm
Products
fastconnect 6800 firmware, fastconnect 6900 firmware, fastconnect 7800 firmware, qca6391 firmware, qca6426 firmware, qca6436 firmware, qcn9074 firmware, qcs410 firmware, qcs610 firmware, sd865 5g firmware, snapdragon 8 gen 1 firmware, snapdragon 865 5g firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.