Junglewise Threat Intelligence

CVE-2023-33106: Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability

CVE-2023-33106 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2023-12-05

Technologies: Qualcomm Multiple Chipsets. Vendors: Qualcomm.

Executive brief

Multiple Qualcomm chipsets are vulnerable to memory corruption due to an out-of-range pointer offset in the Graphics component. This occurs when submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND interface.

Affected products

  • Qualcomm AR8035 Firmware -
  • Qualcomm CSRA6620 Firmware -

Timeline

  • 2023-12-05: disclosed
  • 2023-12-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-12-05: patched: Qualcomm released security bulletin in December 2023
  • exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.

Related threats