Mem Corruption via Large Sync Points in KGSL_GPU_AUX IOCTL
CVE-2023-33106 Published on December 5, 2023

Use of Out-of-range Pointer Offset in Graphics
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

NVD

Known Exploited Vulnerability

This Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

The following remediation steps are recommended / required by December 26, 2023: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

Vulnerability Analysis

CVE-2023-33106 is exploitable with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. This vulnerability is known to be actively exploited by threat actors. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an Untrusted pointer offset Vulnerability?

The program performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

CVE-2023-33106 has been classified to as an Untrusted pointer offset vulnerability or weakness.


Products Associated with CVE-2023-33106

Want to know whenever a new CVE is published for Qualcomm products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Qualcomm, Inc. Snapdragon: qualcomm ar8035_firmware: qualcomm csra6620_firmware: qualcomm csra6640_firmware: qualcomm fastconnect_6200_firmware: qualcomm fastconnect_6700_firmware: qualcomm fastconnect_6800_firmware: qualcomm fastconnect_6900_firmware: qualcomm fastconnect_7800_firmware: qualcomm flight_rb5_5g_platform_firmware: qualcomm qam8255p_firmware: qualcomm qam8295p_firmware: qualcomm qam8650p_firmware: qualcomm qam8775p_firmware: qualcomm qca6174a_firmware: qualcomm qca6391_firmware: qualcomm qca6426_firmware: qualcomm qca6436_firmware: qualcomm qca6574_firmware: qualcomm qca6574a_firmware: qualcomm qca6574au_firmware: qualcomm qca6595_firmware: qualcomm qca6595au_firmware: qualcomm qca6696_firmware: qualcomm qca6698aq_firmware: qualcomm qca6797aq_firmware: qualcomm qca8081_firmware: qualcomm qca8337_firmware: qualcomm qca9377_firmware: qualcomm qcm2290_firmware: qualcomm qcm4290_firmware: qualcomm qcm4325_firmware: qualcomm qcm4490_firmware: qualcomm qcm5430_firmware: qualcomm qcm6490_firmware: qualcomm qcm8550_firmware: qualcomm qcn6024_firmware: qualcomm qcn9011_firmware: qualcomm qcn9012_firmware: qualcomm qcn9024_firmware: qualcomm qcs2290_firmware: qualcomm qcs410_firmware: qualcomm qcs4290_firmware: qualcomm qcs4490_firmware: qualcomm qcs5430_firmware: qualcomm qcs610_firmware: qualcomm qcs6490_firmware: qualcomm qcs7230_firmware: qualcomm qcs8250_firmware: qualcomm qcs8550_firmware: qualcomm qrb5165m_firmware: qualcomm qrb5165n_firmware: qualcomm_215_mobile_platform_firmware: qualcomm_video_collaboration_vc1_platform_firmware: qualcomm_video_collaboration_vc3_platform_firmware: qualcomm_video_collaboration_vc5_platform_firmware: qualcomm robotics_rb5_platform_firmware: qualcomm sa4150p_firmware: qualcomm sa4155p_firmware: qualcomm sa6145p_firmware: qualcomm sa6150p_firmware: qualcomm sa6155p_firmware: qualcomm sa8145p_firmware: qualcomm sa8150p_firmware: qualcomm sa8155p_firmware: qualcomm sa8195p_firmware: qualcomm sa8255p_firmware: qualcomm sa8295p_firmware: qualcomm sa8770p_firmware: qualcomm sa8775p_firmware: qualcomm sa9000p_firmware: qualcomm sd_8_gen1_5g_firmware: qualcomm sd660_firmware: qualcomm sd865_5g_firmware: qualcomm sd888_firmware: qualcomm sg4150p_firmware: qualcomm sg8275p_firmware: qualcomm sm4125_firmware: qualcomm sm7250p_firmware: qualcomm sm7315_firmware: qualcomm sm7325p_firmware: qualcomm sm8550p_firmware: qualcomm smart_audio_400_platform_firmware: qualcomm snapdragon_4_gen_1_mobile_platform_firmware: qualcomm snapdragon_4_gen_2_mobile_platform_firmware: qualcomm snapdragon_439_mobile_platform_firmware: qualcomm snapdragon_460_mobile_platform_firmware: qualcomm snapdragon_480_5g_mobile_platform_firmware: qualcomm snapdragon_660_mobile_platform_firmware: qualcomm snapdragon_662_mobile_platform_firmware: qualcomm snapdragon_680_4g_mobile_platform_firmware: qualcomm snapdragon_690_5g_mobile_platform_firmware: qualcomm snapdragon_695_5g_mobile_platform_firmware: qualcomm snapdragon_750g_5g_mobile_platform_firmware: qualcomm snapdragon_778g_5g_mobile_platform_firmware: qualcomm snapdragon_780g_5g_mobile_platform_firmware: qualcomm snapdragon_8_gen_1_mobile_platform_firmware: qualcomm snapdragon_8_gen_2_mobile_platform_firmware: qualcomm snapdragon_865_5g_mobile_platform_firmware: qualcomm snapdragon_888_5g_mobile_platform_firmware: qualcomm snapdragon_ar2_gen_1_platform_firmware: qualcomm snapdragon_auto_5g_modem-rf_firmware: qualcomm snapdragon_x12_lte_modem_firmware: qualcomm snapdragon_x55_5g_modem-rf_system_firmware: qualcomm snapdragon_x65_5g_modem-rf_system_firmware: qualcomm snapdragon_xr2_5g_platform_firmware: qualcomm ssg2115p_firmware: qualcomm ssg2125p_firmware: qualcomm sw5100_firmware: qualcomm sw5100p_firmware: qualcomm sxr1230p_firmware: qualcomm sxr2130_firmware: qualcomm sxr2230p_firmware: qualcomm wcd9326_firmware: qualcomm wcd9335_firmware: qualcomm wcd9341_firmware: qualcomm wcd9370_firmware: qualcomm wcd9375_firmware: qualcomm wcd9380_firmware: qualcomm wcd9385_firmware: qualcomm wcd9390_firmware: qualcomm wcd9395_firmware: qualcomm wcn3615_firmware: qualcomm wcn3660b_firmware: qualcomm wcn3680b_firmware: qualcomm wcn3910_firmware: qualcomm wcn3950_firmware: qualcomm wcn3980_firmware: qualcomm wcn3988_firmware: qualcomm wcn3990_firmware: qualcomm wcn6740_firmware: qualcomm wsa8810_firmware: qualcomm wsa8815_firmware: qualcomm wsa8830_firmware: qualcomm wsa8832_firmware: qualcomm wsa8835_firmware: qualcomm wsa8840_firmware: qualcomm wsa8845_firmware: qualcomm wsa8845h_firmware:

Exploit Probability

EPSS
0.16%
Percentile
36.71%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.