ZeroHour

CVE-2023-33106

KEVmass1

Out-of-Range Pointer Memory Corruption in Qualcomm KGSL GPU Driver (Actively Exploited)

CISA: Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability

CVSS 3.1
7.8 high
EPSS
<1%p59
Published
()
KEV added
AI analysis

CVE-2023-33106 is a memory-corruption flaw (use of out-of-range pointer offset, CWE-823/CWE-119) in Qualcomm's KGSL GPU kernel driver, which manages the Adreno graphics stack. It is triggered when a local, low-privileged process submits an AUX command containing a large list of sync points through the IOCTL_KGSL_GPU_AUX_COMMAND ioctl, causing out-of-bounds memory access. A successful attacker, typically a malicious app already running on the device, can corrupt kernel memory and escalate privileges, gaining the high confidentiality, integrity and availability impact reflected in its CVSS 7.8 local-attack score. Affected products include the listed Qualcomm components (FastConnect 6200/6700/6800/6900/7800, QAM8255P/QAM8295P/QAM8650P, Flight RB5 5G Platform, AR8035, CSRA6620/CSRA6640), and the vendor's advisory describes the flaw as spanning multiple chipsets. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, and public reporting indicates it was one of three Qualcomm zero-days actively exploited in targeted Android attacks alongside Adreno GPU issues; no public PoC is known.

What to do: Install Android security updates or firmware from your device/OEM vendor that incorporate Qualcomm's fixes for this CVE, prioritizing devices and systems built on the listed chipsets, and check the Qualcomm security bulletin for the fixed firmware versions for each component. Because exploitation requires local code execution, avoid installing untrusted apps on unpatched devices as an interim mitigation. Organizations subject to BOD 22-01 must apply the vendor remediations per the KEV required action.

Affected
Qualcomm AR8035 firmware
Qualcomm CSRA6620 firmware
Qualcomm CSRA6640 firmware
Qualcomm FastConnect 6200 firmware
Qualcomm FastConnect 6700 firmware
Qualcomm FastConnect 6800 firmware
Qualcomm FastConnect 6900 firmware
Qualcomm FastConnect 7800 firmware
Qualcomm Flight RB5 5G Platform firmware
Qualcomm QAM8255P firmware
Qualcomm QAM8295P firmware
Qualcomm QAM8650P firmware
Estimated exposure
mass~hundreds of millions of devices (Qualcomm silicon across Android phones, automotive and IoT platforms); exact count unknown — Qualcomm supplies the majority of Android smartphone silicon and connectivity (the listed FastConnect modules ship inside flagship handsets), and the affected components also appear in automotive (QAM8xxx), drone (Flight RB5) and embedded…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

CISA Known Exploited Vulnerability
Affected
Qualcomm Multiple Chipsets
Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
qualcomm
Products
ar8035 firmware, csra6620 firmware, csra6640 firmware, fastconnect 6200 firmware, fastconnect 6700 firmware, fastconnect 6800 firmware, fastconnect 6900 firmware, fastconnect 7800 firmware, flight rb5 5g platform firmware, qam8255p firmware, qam8295p firmware, qam8650p firmware
Weakness
CWE-823, CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news