CVE-2023-28583
Published Jan 2, 2024Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.
Vendor/product archive
258 CVEs tagged to qualcomm / qca6574au_firmware — 34 Critical, 150 High, 74 Medium, 0 Low, 0 Unrated.
Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
Memory Corruption in camera while installing a fd for a particular DMA buffer.
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
Memory corruption in Audio when SSR event is triggered after music playback is stopped.
Memory corruption in Automotive Display while destroying the image handle created using connected display driver.
Memory corruption while parsing the ADSP response command.
Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).
Weak configuration in Automotive while VM is processing a listener request from TEE.
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
Memory Corruption while accessing metadata in Display.
Memory corruption in Audio while validating and mapping metadata.
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
Memory Corruption due to improper validation of array index in Linux while updating adn record.
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
Information disclosure in Automotive multimedia due to buffer over-read.
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
Memory corruption in RIL while trying to send apdu packet.
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.