Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.qualcomm.com/company/product-security/bulletins/october-2021-bulletin | vendor advisory |