Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
Summary
| CVE | CVE-2023-33106 |
|---|---|
| State | RESERVED |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-12-05 03:15:00 UTC |
| Updated | 2023-12-05 13:51:00 UTC |
| Description | Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. |
Risk And Classification
EPSS: 0.001700000 probability, percentile 0.381420000 (date 2026-04-01)
CISA KEV: Listed on 2023-12-05; due 2023-12-26; ransomware use Unknown
CISA Known Exploited Vulnerability
| Vendor | Qualcomm |
|---|---|
| Product | Multiple Chipsets |
| Name | Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability |
| Required Action | Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. |
| Notes | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/1e46e81dbeb69aafd5842ce779f07e617680fd58; https://nvd.nist.gov/vuln/detail/CVE-2023-33106 |
There are no known software configurations currently associated with this CVE in NVD or the CVE Program record.
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin | www.qualcomm.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.