CVE-2023-21630Integer Underflow (Wrap or Wraparound) in INC Snapdragon

Severity
7.8HIGHNVD
EPSS
0.1%
top 72.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13

Description

Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon40 versions+39

Patches

🔴Vulnerability Details

1
GHSA
GHSA-r744-phrq-6w44: Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal2023-04-13

📋Vendor Advisories

1
Android
CVE-2023-21630: Closed-source component2023-04-01