cross-posted from: https://infosec.pub/post/18563178

Qualcomm has released security patches for a zero-day vulnerability in the Digital Signal Processor (DSP) service that impacts dozens of chipsets. […]

  • Possibly linux
    link
    fedilink
    English
    arrow-up
    6
    ·
    23 hours ago

    If only Android was based on mainline Linux! Who am I joking, cost is way more important than security.

    Serious question though, can this be exploited via web assembly? Also is Lineage OS shipping patches? I know many devices have been abandoned by the vendors so it is entirely possible this will go unpatched in older devices

    • limerod@reddthat.comM
      link
      fedilink
      English
      arrow-up
      3
      ·
      23 hours ago

      Also is Lineage OS shipping patches? I know many devices have been abandoned by the vendors so it is entirely possible this will go unpatched in older devices

      This is a vulnerability in a proprietary Qualcomm’s DSP. The patch will only be made available to OEMs. LineageOS cannot patch this vulnerability if the device itself is no longer receiving official updates.

      • ReversalHatchery@beehaw.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 minutes ago

        how and when is the DSP used, though?

        and what kind of code can take advantage of this? apps? javascript in browser apps? or a non-app system process with a specific privilege?