In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.
Many functions responsible for processing 802.11 (Wi-Fi) standard frames lack proper input data validation. Insufficient buffer boundary control (CWE-125 — out-of-bounds read, CWE-126 — buffer over-read) allows reading data outside the intended memory area. Specially crafted Wi-Fi frames sent to a vulnerable device can trigger this error without any user interaction.
An attacker within wireless network range can gain unauthorized access to sensitive data stored in device memory, and in extreme cases compromise the confidentiality, integrity, and availability of the system.
Apply patches available from the vendor according to the references — Qualcomm security bulletin from May 2018: https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html. OEM device manufacturers using the mentioned chipsets should deploy firmware updates for their products.
Firmware of Qualcomm SD 450, Qualcomm SD 625, and Qualcomm SD 820 chipsets — versions indicated in the vendor's references (Qualcomm security bulletin from May 2018)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HQualcomm Sd 450
HWQualcommall versionsQualcomm Sd 450 Firmware
OSQualcommall versionsQualcomm Sd 625
HWQualcommall versionsQualcomm Sd 625 Firmware
OSQualcommall versionsQualcomm Sd 820
HWQualcommall versionsQualcomm Sd 820a
HWQualcommall versionsQualcomm Sd 820a Firmware
OSQualcommall versionsQualcomm Sd 820 Firmware
OSQualcommall versionsQualcomm Sd 835
HWQualcommall versionsQualcomm Sd 835 Firmware
OSQualcommall versionsQualcomm Sd 845
HWQualcommall versionsQualcomm Sd 845 Firmware
OSQualcommall versionsQualcomm Sd 850
HWQualcommall versionsQualcomm Sd 850 Firmware
OSQualcommall versions
Related vulnerabilities
Qualcomm: Nieprawidłowy dostęp do pamięci przy dekodowaniu VP9 (sprzętowe)
Qualcomm Touch Pal – zbieranie danych o użytkowniku bez jego wiedzy
Qualcomm Snapdragon: out-of-bounds read przy przetwarzaniu IE w ramkach pomiarowych
Buffer overflow w parserze multimediów Qualcomm — podatność krytyczna
Use-after-free w kernelu Qualcomm — dostęp do zwolnionych sesji mdlog