CRITICAL🇵🇱 Wersja polska

CVE-2023-33032

CVSS 9.3v3.1pub. 2024-01-02upd. 2024-11-21

Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

🤖 AI Analysis
How it works

The vulnerability stems from an integer overflow (CWE-190) leading to out-of-bounds write (CWE-787) during memory allocation request handling in TZ Secure OS. The process occurs within the Trusted Execution Environment (TEE) context when a Trusted Application submits a memory allocation request from a dedicated TA region. Incorrect allocation size calculation may result in overwriting critical data structures beyond the intended memory area.

Impact

An attacker may cause memory corruption within TrustZone Secure OS, which potentially enables unauthorized access to sensitive data, system integrity violations, and destabilization or takeover of the secure execution environment with privilege escalation capabilities.

Mitigation & patch

Apply patches available from the manufacturer according to references — Qualcomm security bulletin from January 2024 (https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin). OEM device manufacturers using Qualcomm chipsets should implement the provided firmware updates as soon as possible.

Who is affected

Firmware of Qualcomm devices, including: Qualcomm 9205 LTE Modem, Qualcomm AQT1000, Qualcomm AR8031 and other Qualcomm chipsets listed in the manufacturer's security bulletin from January 2024

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Qualcomm 9205 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9205 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Aqt1000

    HW
    Qualcomm
    all versions
  • Qualcomm Aqt1000 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar8031

    HW
    Qualcomm
    all versions
  • Qualcomm Ar8031 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csr8811

    HW
    Qualcomm
    all versions
  • Qualcomm Csr8811 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6620

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6620 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6640

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6640 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csrb31024

    HW
    Qualcomm
    all versions
  • Qualcomm Csrb31024 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm C V2x 9150

    HW
    Qualcomm
    all versions
  • Qualcomm C V2x 9150 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6800

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6800 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fsm10056

    HW
    Qualcomm
    all versions
  • Qualcomm Fsm10056 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ipq6000

    HW
    Qualcomm
    all versions
  • Qualcomm Ipq6000 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ipq6005

    HW
    Qualcomm
    all versions
  • Qualcomm Ipq6005 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ipq6010

    HW
    Qualcomm
    all versions
  • Qualcomm Ipq6010 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ipq6018

    HW
    Qualcomm
    all versions
  • Qualcomm Ipq6018 Firmware

    OS
    Qualcomm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-25289CRITICAL9.6PL ✓same product

Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm

CVE-2025-47372CRITICAL9.0PL ✓same product

Qualcomm: Memory Corruption przy ładowaniu uszkodzonego obrazu ELF

CVE-2025-21483CRITICAL9.8PL ✓same product

Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)

CVE-2025-27034CRITICAL9.8PL ✓same product

Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR

CVE-2025-21450CRITICAL9.1PL ✓same product

Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania