CWE
20
Advisory Published
CVE Published
Updated

CVE-2023-21671: Improper Input Validation in Core

First published: Mon Nov 06 2023(Updated: )

Memory Corruption in Core during syscall for Sectools Fuse comparison feature.

Credit: product-security@qualcomm.com

Affected SoftwareAffected VersionHow to fix
Google Android
All of
Qualcomm Fastconnect 6700 Firmware
Qualcomm Fastconnect 6700
All of
Qualcomm Fastconnect 6900 Firmware
Qualcomm Fastconnect 6900
All of
Google Android
Google Android
All of
Google Android
Google Android
All of
Google Android
Google Android
All of
Qualcomm Qsm8350 Firmware
Qualcomm Qsm8350
All of
Qualcomm Qualcomm Video Collaboration Vc3 Platform Firmware
Qualcomm Qualcomm Video Collaboration Vc3 Platform
All of
Google Android
Google Android
All of
Google Android
Qualcomm Sm7315
All of
Google Android
Google Android
All of
Qualcomm Snapdragon 778g 5g Mobile Platform Firmware
Qualcomm Snapdragon 778g 5g Mobile Platform
All of
Qualcomm Snapdragon 778g\+ 5g Mobile Platform Firmware
Qualcomm Snapdragon 778g\+ 5g Mobile Platform
All of
Qualcomm Snapdragon 780g 5g Mobile Platform Firmware
Qualcomm Snapdragon 780g 5g Mobile Platform
All of
Qualcomm Snapdragon 782g Mobile Platform Firmware
Qualcomm Snapdragon 782g Mobile Platform
All of
Qualcomm Snapdragon 7c\+ Gen 3 Compute Firmware
Qualcomm Snapdragon 7c\+ Gen 3 Compute
All of
Qualcomm Snapdragon 888 5g Mobile Platform Firmware
Qualcomm Snapdragon 888 5g Mobile Platform
All of
Qualcomm Snapdragon 888\+ 5g Mobile Platform Firmware
Qualcomm Snapdragon 888\+ 5g Mobile Platform
All of
Qualcomm Wcd9370 Firmware
Google Android
All of
Google Android
Google Android
All of
Google Android
Google Android
All of
Google Android
Google Android
All of
Google Android
Qualcomm Wcn6740
All of
Google Android
Google Android
All of
Google Android
Google Android

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2023-21671?

    CVE-2023-21671 is a vulnerability that involves improper input validation in Core, resulting in memory corruption during the syscall for Sectools Fuse comparison feature.

  • Which software are affected by CVE-2023-21671?

    The following software are affected by CVE-2023-21671: Qualcomm Fastconnect 6700 Firmware, Qualcomm Fastconnect 6900 Firmware, Google Android, Qualcomm QCA6391 Firmware, Qualcomm QCM6490 Firmware, Qualcomm QCS6490 Firmware, Qualcomm Qsm8350 Firmware, Qualcomm Qualcomm Video Collaboration VC3 Platform Firmware, Qualcomm Snapdragon 778g 5g Mobile Platform Firmware, Qualcomm Snapdragon 778g+ 5g Mobile Platform Firmware, Qualcomm Snapdragon 780g 5g Mobile Platform Firmware, Qualcomm Snapdragon 782g Mobile Platform Firmware, Qualcomm Snapdragon 7c+ Gen 3 Compute Firmware, Qualcomm Snapdragon 888 5g Mobile Platform Firmware, Qualcomm Snapdragon 888+ 5g Mobile Platform Firmware, Qualcomm Wcd9370 Firmware, Qualcomm Wcd9375 Firmware, Qualcomm Wcd9380 Firmware, Qualcomm Wcd9385 Firmware, Qualcomm Wcn6740 Firmware, Qualcomm Wsa8830 Firmware, Qualcomm Wsa8835 Firmware.

  • What is the severity of CVE-2023-21671?

    The severity of CVE-2023-21671 is critical with a severity value of 9.3.

  • How does CVE-2023-21671 impact the affected software?

    CVE-2023-21671 can lead to memory corruption in the affected software, specifically during the syscall for the Sectools Fuse comparison feature.

  • How can I fix CVE-2023-21671?

    To fix CVE-2023-21671, it is recommended to apply the necessary security updates provided by the software vendor. Please refer to the vendor's security bulletin for more information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203