First published: Tue May 02 2023(Updated: )
Memory corruption in HAB Memory management due to broad system privileges via physical address.
Credit: product-security@qualcomm.com product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm QAM8295P | ||
Qualcomm QAM8295P | ||
All of | ||
Qualcomm QCA6574AU | ||
Qualcomm QCA6574 Firmware | ||
All of | ||
Qualcomm QCA6696 Firmware | ||
Qualcomm QCA6696 Firmware | ||
All of | ||
Qualcomm SA6145P Firmware | ||
Qualcomm SA6145P Firmware | ||
All of | ||
Qualcomm SA6150P Firmware | ||
Qualcomm SA6150P Firmware | ||
All of | ||
Qualcomm SA6155P | ||
Qualcomm SA6155 | ||
All of | ||
Qualcomm SA8145P | ||
Qualcomm SA8145P Firmware | ||
All of | ||
Qualcomm SA8150P Firmware | ||
Qualcomm SA8150P Firmware | ||
All of | ||
Qualcomm SA8155 | ||
Qualcomm SA8155P Firmware | ||
All of | ||
Qualcomm SA8195P | ||
Qualcomm SA8195P Firmware | ||
All of | ||
Qualcomm SA8295P Firmware | ||
Qualcomm SA8295P Firmware | ||
All of | ||
Qualcomm SA8540P | ||
Qualcomm SA8540P Firmware | ||
All of | ||
Qualcomm SA9000P Firmware | ||
Qualcomm SA9000P Firmware | ||
Qualcomm QAM8295P | ||
Qualcomm QAM8295P | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm QCA6696 Firmware | ||
Qualcomm QCA6696 Firmware | ||
Qualcomm SA6145P Firmware | ||
Qualcomm SA6145P Firmware | ||
Qualcomm SA6150P Firmware | ||
Qualcomm SA6150P Firmware | ||
Qualcomm SA6155 | ||
Qualcomm SA6155P | ||
Qualcomm SA8145P | ||
Qualcomm SA8145P Firmware | ||
Qualcomm SA8150P Firmware | ||
Qualcomm SA8150P Firmware | ||
Qualcomm SA8155 | ||
Qualcomm SA8155P Firmware | ||
Qualcomm SA8195P | ||
Qualcomm SA8195P Firmware | ||
Qualcomm SA8295P Firmware | ||
Qualcomm SA8295P Firmware | ||
Qualcomm SA8540P | ||
Qualcomm SA8540P Firmware | ||
Qualcomm SA9000P Firmware | ||
Qualcomm SA9000P Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21642 is a vulnerability that occurs due to memory corruption in HAB Memory management on Qualcomm devices, allowing an attacker with broad system privileges via a physical address.
CVE-2023-21642 affects Qualcomm devices with Qam8295p, Qca6574au, Qca6696, Sa6145p, Sa6150p, Sa6155p, Sa8145p, Sa8150p, Sa8155p, Sa8195p, Sa8295p, Sa8540p, or Sa9000p firmware, and it can lead to memory corruption and unauthorized access.
CVE-2023-21642 has a severity score of 7.8, which is considered high.
The official reference for CVE-2023-21642 can be found at https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin.
To fix CVE-2023-21642, it is recommended to apply the security patches provided by Qualcomm for the affected devices.