On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
In certain hardware revisions where VP9 decoding is hardware-based, the frame size is not correctly programmed in the decoder chip. This results in the decoder being able to access an incorrect memory region while processing the video stream. The flaw falls under the category of CWE-823 (use of out-of-range pointer offset) and CWE-119 (improper restriction of operations within a memory buffer).
An attacker can compromise the confidentiality, integrity, and availability of the system, potentially executing arbitrary code or causing device failure through a crafted VP9 video stream.
Apply patches available from the manufacturer according to the references — Qualcomm security bulletin from May 2018: https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html
Qualcomm MSM8909W Firmware, Qualcomm MSM8996AU Firmware, Qualcomm SD 210 Firmware — specific affected hardware revisions indicated in the Qualcomm security bulletin from May 2018
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HQualcomm Msm8909w
HWQualcommall versionsQualcomm Msm8909w Firmware
OSQualcommall versionsQualcomm Msm8996au
HWQualcommall versionsQualcomm Msm8996au Firmware
OSQualcommall versionsQualcomm Sd 205
HWQualcommall versionsQualcomm Sd 205 Firmware
OSQualcommall versionsQualcomm Sd 210
HWQualcommall versionsQualcomm Sd 210 Firmware
OSQualcommall versionsQualcomm Sd 212
HWQualcommall versionsQualcomm Sd 212 Firmware
OSQualcommall versionsQualcomm Sd 415
HWQualcommall versionsQualcomm Sd 415 Firmware
OSQualcommall versionsQualcomm Sd 425
HWQualcommall versionsQualcomm Sd 425 Firmware
OSQualcommall versionsQualcomm Sd 427
HWQualcommall versionsQualcomm Sd 427 Firmware
OSQualcommall versionsQualcomm Sd 430
HWQualcommall versionsQualcomm Sd 430 Firmware
OSQualcommall versionsQualcomm Sd 435
HWQualcommall versionsQualcomm Sd 435 Firmware
OSQualcommall versionsQualcomm Sd 450
HWQualcommall versionsQualcomm Sd 450 Firmware
OSQualcommall versionsQualcomm Sd 615
HWQualcommall versionsQualcomm Sd 615 Firmware
OSQualcommall versionsQualcomm Sd 616
HWQualcommall versionsQualcomm Sd 616 Firmware
OSQualcommall versionsQualcomm Sd 625
HWQualcommall versionsQualcomm Sd 625 Firmware
OSQualcommall versionsQualcomm Sd 810
HWQualcommall versionsQualcomm Sd 810 Firmware
OSQualcommall versions
Related vulnerabilities
Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)
Qualcomm SD 450/625/820 — odczyt poza granicami bufora w obsłudze ramek 802.11
Qualcomm Touch Pal – zbieranie danych o użytkowniku bez jego wiedzy
Pominięcie uwierzytelnienia w sieciach LTE w modemach Qualcomm
Memory corruption w HLOS podczas obsługi PlayReady w chipsetach Qualcomm