Описание
Уязвимость драйвера Camera Driver микропрограммного обеспечения встраиваемых плат Qualcomm связана с записью за границами буфера при обработке параметров input batch size и buffer plane count. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Вендор
Qualcomm Technologies Inc.
Наименование ПО
SD 8 Gen1 5G
WCD9380
WSA8830
WSA8835
WCD9371
Snapdragon XR2 5G Platform
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 460 Mobile Platform
Snapdragon 662 Mobile Platform
Snapdragon XR2+ Gen 1 Platform
Snapdragon 8 Gen 2 Mobile Platform
Snapdragon 8+ Gen 2 Mobile Platform
SA8770P
QCA6678AQ
SA7775P
SA8620P
SRV1H
SRV1M
WCN7860
WCN7861
WCN7881
FastConnect 6700
FastConnect 6900
FastConnect 7800
QCS4490
QCM4490
WCD9370
WCD9390
WCD9395
WCN3950
WSA8810
WSA8815
WSA8832
WSA8840
WSA8845
WSA8845H
QAM8255P
QAMSRV1H
QAMSRV1M
QCA6595
QCA6595AU
QCA6698AQ
QCA6797AQ
QCS8550
SA7255P
SA8255P
SA9000P
SM8550P
SXR2230P
SXR2330P
WCD9375
WCD9378
WCD9385
WCN3988
WCN6450
WCN6650
WCN6755
Snapdragon AR1 Gen 1 Platform
SM7435
QCA6698AU
SC8380XP
SD865 5G
Snapdragon 4 Gen 2 Mobile Platform
SXR2350P
SM7550
SM7550P
Snapdragon 6 Gen 1 Mobile Platform
Snapdragon 7 Gen 1 Mobile Platform
IQ9 Series Platform
LeMans_AU_LGIT
LeMansAU
Netrani
Pandeiro
QLN1083BD
QLN1086BD
QPA1083BD
QPA1086BD
QXM1093
QXM1094
QXM1095
QXM1096
SAR2130P
Snapdragon 6 Gen 3 Mobile Platform
Snapdragon 8 Elite
XRV7209
XRV9209
G3x Gen 2
SM7525
X1E80100
QCM8838
SDR753
Версия ПО
- (SD 8 Gen1 5G)
- (WCD9380)
- (WSA8830)
- (WSA8835)
- (WCD9371)
- (Snapdragon XR2 5G Platform)
- (Snapdragon 8 Gen 1 Mobile Platform)
- (Snapdragon 460 Mobile Platform)
- (Snapdragon 662 Mobile Platform)
- (Snapdragon XR2+ Gen 1 Platform)
- (Snapdragon 8 Gen 2 Mobile Platform)
- (Snapdragon 8+ Gen 2 Mobile Platform)
- (SA8770P)
- (QCA6678AQ)
- (SA7775P)
- (SA8620P)
- (SRV1H)
- (SRV1M)
- (WCN7860)
- (WCN7861)
- (WCN7881)
- (FastConnect 6700)
- (FastConnect 6900)
- (FastConnect 7800)
- (QCS4490)
- (QCM4490)
- (WCD9370)
- (WCD9390)
- (WCD9395)
- (WCN3950)
- (WSA8810)
- (WSA8815)
- (WSA8832)
- (WSA8840)
- (WSA8845)
- (WSA8845H)
- (QAM8255P)
- (QAMSRV1H)
- (QAMSRV1M)
- (QCA6595)
- (QCA6595AU)
- (QCA6698AQ)
- (QCA6797AQ)
- (QCS8550)
- (SA7255P)
- (SA8255P)
- (SA9000P)
- (SM8550P)
- (SXR2230P)
- (SXR2330P)
- (WCD9375)
- (WCD9378)
- (WCD9385)
- (WCN3988)
- (WCN6450)
- (WCN6650)
- (WCN6755)
- (Snapdragon AR1 Gen 1 Platform)
- (SM7435)
- (QCA6698AU)
- (SC8380XP)
- (SD865 5G)
- (Snapdragon 4 Gen 2 Mobile Platform)
- (SXR2350P)
- (SM7550)
- (SM7550P)
- (Snapdragon 6 Gen 1 Mobile Platform)
- (Snapdragon 7 Gen 1 Mobile Platform)
- (IQ9 Series Platform)
- (LeMans_AU_LGIT)
- (LeMansAU)
- (Netrani)
- (Pandeiro)
- (QLN1083BD)
- (QLN1086BD)
- (QPA1083BD)
- (QPA1086BD)
- (QXM1093)
- (QXM1094)
- (QXM1095)
- (QXM1096)
- (SAR2130P)
- (Snapdragon 6 Gen 3 Mobile Platform)
- (Snapdragon 8 Elite)
- (XRV7209)
- (XRV9209)
- (G3x Gen 2)
- (SM7525)
- (X1E80100)
- (QCM8838)
- (SDR753)
Тип ПО
Микропрограммный код
Микропрограммный код аппаратных компонентов компьютера
Операционные системы и аппаратные платформы
-
Уровень опасности уязвимости
Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 3,5)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,3)
Возможные меры по устранению уязвимости
Использование рекомендаций производителя:
https://docs.qualcomm.com/securitybulletin/july-2026-bulletin.html#_cve-2026-21370
https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel/-/commit/2384bb3718b1116ec4964faa59127d52e3ec1804
https://git.codelinaro.org/clo/le/platform/vendor/opensource/camera-kernel/-/commit/295c217dff61515eb8e695721b4334e170e95553
Статус уязвимости
Подтверждена производителем
Наличие эксплойта
Данные уточняются
Информация об устранении
Уязвимость устранена
Ссылки на источники
Идентификаторы других систем описаний уязвимостей
- CVE
EPSS
Процентиль: 0%
0.00079
Низкий
5.3 Medium
CVSS3
3.5 Low
CVSS2
Связанные уязвимости
CVSS3: 5.3
nvd
3 месяца назад
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
CVSS3: 5.3
github
3 месяца назад
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
EPSS
Процентиль: 0%
0.00079
Низкий
5.3 Medium
CVSS3
3.5 Low
CVSS2