ZeroHour

CVE-2021-1906

KEVmass

GPU Address Allocation DoS in Qualcomm Snapdragon and IoT Chipsets

CISA: Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

CVSS 3.1
5.5 medium
EPSS
<1%p43
Published
()
KEV added
AI analysis

CVE-2021-1906 is an availability flaw in the GPU component of numerous Qualcomm chipsets: improper handling of address deregistration on failure can cause subsequent new GPU address allocations to fail. A local attacker with low privileges (for example, a malicious or compromised app or process on an Android device) can trigger the failure condition, causing GPU allocation failures that can hang or crash the affected device. The CVSS vector (C:N/I:N/A:H) confirms there is no confidentiality or integrity impact, so the attacker gains denial of service rather than code execution or data theft. It affects firmware for Qualcomm APQ8009, APQ8009W, APQ8017, APQ8053, APQ8064AU, APQ8096AU, AQT1000, AR8031, AR8035, AR8151, CSRA6620, and CSRA6640 across Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables product lines. CISA added the vulnerability to the KEV catalog on 2021-11-03, and it was addressed in Android security updates alongside other Qualcomm and Arm zero-days that Google reported as being used in targeted attacks.

What to do: Install the November 2021 (or later) Android security bulletin and Qualcomm-supplied fixes on affected phones, tablets, and embedded devices, and obtain updated firmware from device/OEM vendors for Snapdragon-based automotive, IoT, and connectivity products. Because the flaw is only exploitable locally with low privileges, exposure requires attacker code already running on the device, so applying vendor updates and checking chipset model (APQ8009/APQ8009W/APQ8017/APQ8053/APQ8064AU/APQ8096AU/AQT1000/AR8031/AR8035/AR8151/CSRA6620/CSRA6640) to confirm applicability are the key actions.

Affected
Qualcomm APQ8009 firmware
Qualcomm APQ8009W firmware
Qualcomm APQ8017 firmware
Qualcomm APQ8053 firmware
Qualcomm APQ8064AU firmware
Qualcomm APQ8096AU firmware
Qualcomm AQT1000 firmware
Qualcomm AR8031 firmware
Qualcomm AR8035 firmware
Qualcomm AR8151 firmware
Qualcomm CSRA6620 firmware
Qualcomm CSRA6640 firmware
Estimated exposure
masshundreds of millions of devices (affected Qualcomm/Snapdragon chipsets ship across mainstream Android smartphones, automotive, and embedded IoT products) — The affected chipsets (e.g., APQ8009 and APQ8053 families) are widely deployed in budget-to-midrange Android handsets plus automotive and IoT hardware, so the global install base plausibly runs to the hundreds of millions, though the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CISA Known Exploited Vulnerability
Affected
Qualcomm Multiple Chipsets
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
qualcomm
Products
apq8009 firmware, apq8009w firmware, apq8017 firmware, apq8053 firmware, apq8064au firmware, apq8096au firmware, aqt1000 firmware, ar8031 firmware, ar8035 firmware, ar8151 firmware, csra6620 firmware, csra6640 firmware
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news