Executive brief
A use-after-free vulnerability exists in multiple Qualcomm chipsets when process shell memory is freed via an IOCTL munmap call while process initialization is still in progress. This flaw can lead to memory corruption and potential privilege escalation.
Affected products
- Qualcomm Snapdragon Auto
- Qualcomm Snapdragon Compute
- Qualcomm Snapdragon Connectivity
- Qualcomm Snapdragon Consumer IOT
- Qualcomm Snapdragon Industrial IOT
- Qualcomm Snapdragon Mobile
- Qualcomm Snapdragon Voice & Music
- Qualcomm APQ8053 Firmware -
- Qualcomm AR8031 Firmware -
Timeline
- 2022-05-01: patched: Qualcomm released a security bulletin in May 2022 addressing the issue.
- 2023-12-05: disclosed: NVD publication date.
- 2023-12-05: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2023-12-05: exploited: Confirmed as exploited in the wild per CISA KEV catalog.