Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile
References
Link | Resource |
---|---|
https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletin | Patch Vendor Advisory |
https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletin | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
History
21 Nov 2024, 06:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletin - Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 6.9
v3 : 8.4 |
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-502 |
19 Apr 2023, 17:10
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:qualcomm:sm8475:-:*:*:*:*:*:*:* |
22 Jun 2022, 19:30
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-362 | |
CVSS |
v2 : v3 : |
v2 : 6.9
v3 : 7.0 |
References | (CONFIRM) https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletin - Patch, Vendor Advisory | |
CPE | cpe:2.3:o:qualcomm:sdx65_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:sdx65:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wcn6855_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wcn6855:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:qca8337:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wcn6856_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:qca8081:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:sd_8_gen1_5g_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:sd_8_gen1_5g:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:qca8337_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wcn6856:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:ar8035:-:*:*:*:*:*:*:* |
14 Jun 2022, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-14 10:15
Updated : 2024-11-21 06:11
NVD link : CVE-2021-35095
Mitre link : CVE-2021-35095
CVE.ORG link : CVE-2021-35095
JSON object : View
Products Affected
qualcomm
- qca8337_firmware
- sdx65_firmware
- ar8035_firmware
- wsa8830
- wcd9380
- qca8337
- wsa8830_firmware
- wsa8835
- sd_8_gen1_5g_firmware
- ar8035
- qca8081
- sdx65
- sm8475
- wcn6856_firmware
- wcn6855_firmware
- wsa8835_firmware
- wcd9380_firmware
- wcn6856
- wcn6855
- qca8081_firmware
CWE
CWE-502
Deserialization of Untrusted Data