First published: Tue Jul 04 2023(Updated: )
Memory corruption in Linux when the file upload API is called with parameters having large buffer.
Credit: product-security@qualcomm.com product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm FastConnect 6900 Firmware | ||
Qualcomm Fastconnect 6900 Firmware | ||
All of | ||
Qualcomm Fastconnect 7800 Firmware | ||
Qualcomm Fastconnect 7800 Firmware | ||
All of | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Firmware | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Firmware | ||
All of | ||
Qualcomm WCD9380 | ||
Qualcomm WCD9380 Firmware | ||
All of | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8830 | ||
All of | ||
Qualcomm WSA8835 | ||
Qualcomm WSA8835 Firmware | ||
Qualcomm FastConnect 6900 Firmware | ||
Qualcomm Fastconnect 6900 Firmware | ||
Qualcomm Fastconnect 7800 Firmware | ||
Qualcomm Fastconnect 7800 Firmware | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Firmware | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Firmware | ||
Qualcomm WCD9380 | ||
Qualcomm WCD9380 Firmware | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8835 | ||
Qualcomm WSA8835 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21640 is a vulnerability that allows memory corruption in Linux when the file upload API is called with parameters having large buffer.
The affected software includes Qualcomm Fastconnect 6900 Firmware, Qualcomm Fastconnect 7800 Firmware, and Qualcomm Snapdragon 8 Gen 1 Firmware.
The severity of CVE-2023-21640 is high with a CVSS score of 7.8.
To fix CVE-2023-21640, apply the security patch provided by Qualcomm. More details can be found in the official bulletin.
You can find more information about CVE-2023-21640 in the official Qualcomm July 2023 bulletin.