CVE-2023-33106
Published Dec 5, 2023Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
- evidence mentions
- 8
- Buzz score
- 56.5
Vendor/product archive
196 CVEs tagged to qualcomm / qam8295p_firmware — 11 Critical, 127 High, 58 Medium, 0 Low, 0 Unrated.
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
Memory corruption in Core while processing RX intent request.
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
Memory corruption while sending SMS from AP firmware.
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
Memory Corruption in camera while installing a fd for a particular DMA buffer.
Memory corruption in Audio when SSR event is triggered after music playback is stopped.
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
Memory corruption while processing audio effects.
Memory corruption in Automotive Display while destroying the image handle created using connected display driver.
Memory corruption while parsing the ADSP response command.
Memory corruption in DSP Service during a remote call from HLOS to DSP.
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
Memory Corruption in HLOS while registering for key provisioning notify.
Weak configuration in Automotive while VM is processing a listener request from TEE.
Improper Access to the VM resource manager can lead to Memory Corruption.
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).
Memory Corruption in Core Platform while printing the response buffer in log.
Memory corruption in Core Platform while printing the response buffer in log.
Memory corruption in Audio during playback session with audio effects enabled.
Information disclosure in Automotive multimedia due to buffer over-read.
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
Transient DOS in Audio while remapping channel buffer in media codec decoding.