November

HUAWEI is releasing monthly security updates for flagship models. This security update includes HUAWEI and third-party library patches:

This security update includes the following third-party library patches:

This security update includes the CVE announced in the October 2023 Android security bulletin:

Critical: CVE-2023-4863

High: CVE-2023-40128, CVE-2023-21266, CVE-2023-40121, CVE-2023-40123, CVE-2023-40133, CVE-2023-40134, CVE-2023-40135, CVE-2023-40136, CVE-2023-40137, CVE-2023-40138, CVE-2023-40139, CVE-2023-40140, CVE-2023-40125, CVE-2023-40127, CVE-2023-40130, CVE-2023-33034, CVE-2023-33035, CVE-2023-21394

Medium: none

Low: none

Already included in previous updates: CVE-2023-21281, CVE-2022-20281, CVE-2023-21177

※ For more information on security patches, please refer to the Android security bulletins (https://source.android.com/security/bulletin).

This security update includes the following HUAWEI patches:

CVE-2022-48613: Race condition vulnerability in the kernel module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.0

Impact: Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.

CVE-2023-44098: Vulnerability of missing encryption in the card management module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVE-2023-44115: Vulnerability of improper permission control in the Booster module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 12.0.0

Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVE-2023-46755: Vulnerability of input parameters being not strictly verified in the input method module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0

Impact: Successful exploitation of this vulnerability may cause the launcher to restart.

CVE-2023-46756: Permission control vulnerability in the window management module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability may cause malicious pop-up windows.

CVE-2023-46758: Permission management vulnerability in the multi-screen interaction module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability may cause service exceptions of the device.

CVE-2023-46759: Permission control vulnerability in the call module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVE-2023-46760: Out-of-bounds write vulnerability in the kernel driver module

Severity: Medium

Affected versions: EMUI 13.0.0

Impact: Successful exploitation of this vulnerability may cause process exceptions.

CVE-2023-46761: Out-of-bounds write vulnerability in the kernel driver module

Severity: Medium

Affected versions: EMUI 13.0.0

Impact: Successful exploitation of this vulnerability may cause process exceptions.

CVE-2023-46762: Out-of-bounds write vulnerability in the kernel driver module

Severity: Medium

Affected versions: EMUI 13.0.0

Impact: Successful exploitation of this vulnerability may cause process exceptions.

CVE-2023-46763: Vulnerability of background app permission management in the framework module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability may cause background apps to start maliciously.

CVE-2023-46764: Unauthorized startup vulnerability of background apps

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability may cause background apps to start maliciously.

CVE-2023-46765: Vulnerability of uncaught exceptions in the NFC module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 12.0.0, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability can affect NFC availability.

CVE-2023-46766: Out-of-bounds write vulnerability in the kernel driver module

Severity: Medium

Affected versions: EMUI 13.0.0

Impact: Successful exploitation of this vulnerability may cause process exceptions.

CVE-2023-46767: Out-of-bounds write vulnerability in the kernel driver module

Severity: Medium

Affected versions: EMUI 13.0.0

Impact: Successful exploitation of this vulnerability may cause process exceptions.

CVE-2023-46768: Multi-thread vulnerability in the idmap module

Severity: High

Affected versions: EMUI 13.0.0

Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

CVE-2023-46769: Use-After-Free (UAF) vulnerability in the dubai module

Severity: High

Affected versions: EMUI 13.0.0

Impact: Successful exploitation of this vulnerability will affect availability.

CVE-2023-46770: Out-of-bounds vulnerability in the sensor module

Severity: High

Affected versions: EMUI 13.0.0, EMUI 12.0.0

Impact: Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

CVE-2023-46771: Security vulnerability in the face unlock module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.0

Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVE-2023-46772: Vulnerability of parameters being out of the value range in the QMI service module

Severity: Medium

Affected versions: EMUI 11.0.1

Impact: Successful exploitation of this vulnerability may cause errors in reading file data.

CVE-2023-46774: Vulnerability of uncaught exceptions in the NFC module

Severity: Medium

Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 12.0.0, EMUI 11.0.1

Impact: Successful exploitation of this vulnerability can affect NFC availability.

CVE-2023-5801: Vulnerability of identity verification being bypassed in the face unlock module

Severity: Critical

Affected versions: EMUI 13.0.0, EMUI 12.0.0

Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Leaving consumer.huawei.com
After clicking the link, you will enter a third-party website. Huawei is not responsible and has no control over this third party website.
Return Continue