ZeroHour

CVE-2023-33107

KEVmass

Integer Overflow in Qualcomm Graphics Linux (Adreno GPU) Driver - Actively Exploited

CISA: Qualcomm Multiple Chipsets Integer Overflow Vulnerability

CVSS 3.1
7.8 high
EPSS
<1%p58
Published
()
KEV added
AI analysis

CVE-2023-33107 is an integer overflow (CWE-190) in the Graphics Linux component of Qualcomm's Adreno GPU driver stack that causes memory corruption while assigning a shared virtual memory region during an IOCTL call. A local, low-privileged application can trigger the bug by issuing the affected IOCTL, and successful exploitation yields kernel-level memory corruption with high impact on confidentiality, integrity, and availability, in practice local privilege escalation on the device. Exposure spans Android/Linux devices built on numerous Qualcomm chipsets: CISA lists 'Qualcomm Multiple Chipsets,' and the CPE data covers a dozen firmware families including Qualcomm 315 5G IoT Modem, APQ8017/APQ8064AU, AQT1000, AR8031/AR8035, C-V2X 9150, CSRA6620/CSRA6640/CSRB31024, and FastConnect 6200/6700. Qualcomm released fixes and details for this flaw as one of three zero-days used in targeted Android attacks via the Adreno GPU, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, confirming in-the-wild exploitation. No public proof-of-concept is known and 30-day EPSS is 0.9% (57th percentile), but defenders should treat it as actively exploited given the KEV listing and vendor confirmation.

What to do: Apply updated Qualcomm chipset firmware and GPU driver packages per the vendor security bulletin (shipped alongside fixes for the companion zero-days exploited via the Adreno GPU), and on Android fleets install OEM/Google security updates that include the Qualcomm fix, inventorying devices by chipset first. As a CISA KEV entry (added 2023-12-05), the required action is to apply vendor remediations or mitigations, or discontinue use of affected products if fixes are unavailable, with federal agencies bound by BOD 22-01 deadlines. Given reported targeted Android attacks chaining this bug for spyware delivery, review high-risk mobile endpoints for compromise indicators and prioritize patching for exposed or high-value users.

Affected
Qualcomm 315 5G IoT Modem firmware
Qualcomm APQ8017 firmware
Qualcomm APQ8064AU firmware
Qualcomm AQT1000 firmware
Qualcomm AR8031 firmware
Qualcomm AR8035 firmware
Qualcomm C-V2X 9150 firmware
Qualcomm CSRA6620 firmware
Qualcomm CSRA6640 firmware
Qualcomm CSRB31024 firmware
Qualcomm FastConnect 6200 firmware
Qualcomm FastConnect 6700 firmware
Estimated exposure
masshundreds of millions to 1+ billion Android devices (Qualcomm chipset install base) — Qualcomm supplies roughly a third of global smartphone chipsets and the vulnerable Graphics Linux/Adreno GPU driver is bundled across its chipset firmware portfolio, so the plausibly affected install base is at least in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

CISA Known Exploited Vulnerability
Affected
Qualcomm Multiple Chipsets
Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
qualcomm
Products
315 5g iot modem firmware, apq8017 firmware, apq8064au firmware, aqt1000 firmware, ar8031 firmware, ar8035 firmware, c-v2x 9150 firmware, csra6620 firmware, csra6640 firmware, csrb31024 firmware, fastconnect 6200 firmware, fastconnect 6700 firmware
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news