CVE-2023-21648: Integer Overflow to Buffer Overflow in RIL
Memory corruption in RIL while trying to send apdu packet.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21648?
CVE-2023-21648 is a vulnerability related to memory corruption in RIL (Radio Interface Layer) while trying to send an apdu packet.
Which software is affected by CVE-2023-21648?
The software affected by CVE-2023-21648 is Google Android with specific firmware versions of Qualcomm AQT1000, QCA6391, QCA6420, QCA6430, QCA6574a, QCA6574au, QCA6595au, QCA6696, QCC5100, Sa515m, Sa6145p, Sa6150p, Sa6155p, Sa8145p, Sa8150p, Sa8155p, Sa8195p, SD855, SDA429w, SDX55, SW5100, SW5100p, WCD9341, WCD9360, WCN3610, WCN3660b, WCN3680b, WCN3980, WCN3988, WCN3998, WSA8810, WSA8815, WSA8830, and WSA8835.
What is the severity of CVE-2023-21648?
The severity of CVE-2023-21648 is high, with a CVSS score of 7.8.
How does CVE-2023-21648 impact the affected software?
CVE-2023-21648 can result in memory corruption in the RIL component of the affected software while attempting to send an apdu packet, which can lead to potential security risks.
Where can I find more information about CVE-2023-21648?
You can find more information about CVE-2023-21648 in the August 2023 bulletin on the Qualcomm Product Security website.