CVE-2023-22382
Published Oct 3, 2023Weak configuration in Automotive while VM is processing a listener request from TEE.
Vendor/product archive
159 CVEs tagged to qualcomm / qca6696_firmware — 8 Critical, 96 High, 55 Medium, 0 Low, 0 Unrated.
Weak configuration in Automotive while VM is processing a listener request from TEE.
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
Memory Corruption while accessing metadata in Display.
Memory corruption in Audio while validating and mapping metadata.
Transient DOS in Modem while processing invalid System Information Block 1.
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
Memory Corruption due to improper validation of array index in Linux while updating adn record.
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
Information disclosure in Automotive multimedia due to buffer over-read.
Memory corruption in RIL while trying to send apdu packet.
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.
An app with non-privileged access can change global system brightness and cause undesired system behavior.
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
Memory corruption in Automotive GPU while querying a gsl memory node.
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.
Memory corruption in Audio due to incorrect type cast during audio use-cases.
Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.
Memory corruption in HAB Memory management due to broad system privileges via physical address.
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.
Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.