Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
During parsing of beacon or probe response frames sent by an access point (AP), the vulnerable code does not properly verify the number of supported links contained in the MLIE (Multi-Link Information Element). When the AP provides more such links than expected, memory corruption occurs (CWE-823 — improper use of pointer). An attacker controlling or impersonating an access point can send a specially crafted frame and trigger this error on a victim device within the wireless network range.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code (RCE) or cause system crash, leading to violation of confidentiality, integrity, and availability of the device.
Patches available from the manufacturer should be applied according to the references — a detailed list of vulnerable versions and corresponding updates is available in the Qualcomm Product Security Bulletin from March 2024: https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin
Qualcomm AR8035 Firmware, Qualcomm CSR8811 Firmware, Qualcomm FastConnect 6900 Firmware, and other Qualcomm products indicated in the manufacturer's security bulletin from March 2024.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HQualcomm Ar8035
HWQualcommall versionsQualcomm Ar8035 Firmware
OSQualcommall versionsQualcomm Csr8811
HWQualcommall versionsQualcomm Csr8811 Firmware
OSQualcommall versionsQualcomm Fastconnect 6900
HWQualcommall versionsQualcomm Fastconnect 6900 Firmware
OSQualcommall versionsQualcomm Fastconnect 7800
HWQualcommall versionsQualcomm Fastconnect 7800 Firmware
OSQualcommall versionsQualcomm Immersive Home 214
HWQualcommall versionsQualcomm Immersive Home 214 Firmware
OSQualcommall versionsQualcomm Immersive Home 216
HWQualcommall versionsQualcomm Immersive Home 216 Firmware
OSQualcommall versionsQualcomm Immersive Home 316
HWQualcommall versionsQualcomm Immersive Home 316 Firmware
OSQualcommall versionsQualcomm Immersive Home 318
HWQualcommall versionsQualcomm Immersive Home 318 Firmware
OSQualcommall versionsQualcomm Immersive Home 3210
HWQualcommall versionsQualcomm Immersive Home 3210 Firmware
OSQualcommall versionsQualcomm Immersive Home 326
HWQualcommall versionsQualcomm Immersive Home 326 Firmware
OSQualcommall versionsQualcomm Ipq5010
HWQualcommall versionsQualcomm Ipq5010 Firmware
OSQualcommall versionsQualcomm Ipq5028
HWQualcommall versionsQualcomm Ipq5028 Firmware
OSQualcommall versionsQualcomm Ipq5302
HWQualcommall versionsQualcomm Ipq5302 Firmware
OSQualcommall versionsQualcomm Ipq5312
HWQualcommall versionsQualcomm Ipq5312 Firmware
OSQualcommall versionsQualcomm Ipq5332
HWQualcommall versionsQualcomm Ipq5332 Firmware
OSQualcommall versions
Related vulnerabilities
Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm
Qualcomm: Memory Corruption przy ładowaniu uszkodzonego obrazu ELF
Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)
Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR
Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania