Junglewise Threat Intelligence

CVE-2023-33107: Qualcomm Multiple Chipsets Integer Overflow Vulnerability

CVE-2023-33107 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2023-12-05

Technologies: Qualcomm Multiple Chipsets. Vendors: Qualcomm.

Executive brief

An integer overflow vulnerability in Qualcomm Graphics Linux components leads to memory corruption when assigning a shared virtual memory region during an IOCTL call. This flaw allows for potential privilege escalation or system instability.

Affected products

  • Qualcomm 315 5G IoT Modem Firmware -
  • Qualcomm APQ8017 Firmware -

Timeline

  • 2023-12-05: disclosed
  • 2023-12-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-12-05: exploited: Reported as exploited in the wild in the advisory and CISA KEV.

Related threats