Executive brief
Multiple Qualcomm chipsets are vulnerable to memory corruption due to an out-of-range pointer offset in the Graphics component. This occurs when submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND interface.
Affected products
- Qualcomm AR8035 Firmware -
- Qualcomm CSRA6620 Firmware -
Timeline
- 2023-12-05: disclosed
- 2023-12-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-12-05: patched: Qualcomm released security bulletin in December 2023
- exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.