First published: Tue Sep 05 2023(Updated: )
A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).
Credit: product-security@qualcomm.com product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Qcs605 Firmware | ||
Google Android | ||
Qualcomm Qcs405 Firmware | ||
Google Android | ||
All of | ||
Google Android | ||
Google Android | ||
All of | ||
Google Android | ||
Google Android | ||
All of | ||
Google Android | ||
Qualcomm Qcs605 Firmware | ||
All of | ||
Google Android | ||
Qualcomm Qcs405 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-28543 is critical.
CVE-2023-28543 affects the affected software by triggering memory corruption.
CVE-2023-28543 can be exploited by loading a malformed DLC or untrusted model.
The software affected by CVE-2023-28543 includes Google Android (Qualcomm SD855 Firmware) and Qualcomm Qcs605 Firmware.
Please refer to the official reference link for information on fixes and patches for CVE-2023-28543.