CVE-2023-21639: Buffer Copy Without Checking the Size of Input in Audio
Memory corruption in Audio while processing svamodelserializer using memory size passed by HIDL client.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21639?
CVE-2023-21639 is a vulnerability that causes memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
Which software is affected by CVE-2023-21639?
Google Android, Qualcomm Fastconnect 6200 Firmware, Qualcomm Qca6420 Firmware, Qualcomm Qca6430 Firmware, Qualcomm Sa4150p Firmware, Qualcomm Sa8195p Firmware, Qualcomm Snapdragon 855 Firmware, Qualcomm Snapdragon 855+\/860 Firmware, Qualcomm Snapdragon W5+ Gen 1 Firmware, Qualcomm Wcd9341 Firmware.
What is the severity of CVE-2023-21639?
CVE-2023-21639 has a severity rating of 7.8 (high).
How can I fix CVE-2023-21639?
To fix CVE-2023-21639, it is recommended to apply the security patches provided by the vendor.
Where can I find more information about CVE-2023-21639?
You can find more information about CVE-2023-21639 at the following link: [link](https://www.qualcomm.com/company/product-security/bulletins/july-2023-bulletin).