CVE-2023-21648
Published Aug 8, 2023Memory corruption in RIL while trying to send apdu packet.
Vendor/product archive
295 CVEs tagged to qualcomm / qca6391 — 20 Critical, 183 High, 92 Medium, 0 Low, 0 Unrated.
Memory corruption in RIL while trying to send apdu packet.
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
Memory corruption in Linux while calling system configuration APIs.
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
Information disclosure in DSP Services while loading dynamic module.
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
Memory corruption in Linux while sending DRM request.
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
Memory corruption in Linux android due to double free while calling unregister provider after register call.
Assertion occurs while processing Reconfiguration message due to improper validation
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
Memory corruption due to use after free in Modem while modem initialization.
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
Transient DOS in modem due to reachable assertion.
Memory corruption due to improper validation of array index in Multi-mode call processor.
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.