CVE-2023-33107
KEVmassInteger Overflow in Qualcomm Graphics Linux (Adreno GPU) Driver - Actively Exploited
CISA: Qualcomm Multiple Chipsets Integer Overflow Vulnerability
CVE-2023-33107 is an integer overflow (CWE-190) in the Graphics Linux component of Qualcomm's Adreno GPU driver stack that causes memory corruption while assigning a shared virtual memory region during an IOCTL call. A local, low-privileged application can trigger the bug by issuing the affected IOCTL, and successful exploitation yields kernel-level memory corruption with high impact on confidentiality, integrity, and availability, in practice local privilege escalation on the device. Exposure spans Android/Linux devices built on numerous Qualcomm chipsets: CISA lists 'Qualcomm Multiple Chipsets,' and the CPE data covers a dozen firmware families including Qualcomm 315 5G IoT Modem, APQ8017/APQ8064AU, AQT1000, AR8031/AR8035, C-V2X 9150, CSRA6620/CSRA6640/CSRB31024, and FastConnect 6200/6700. Qualcomm released fixes and details for this flaw as one of three zero-days used in targeted Android attacks via the Adreno GPU, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, confirming in-the-wild exploitation. No public proof-of-concept is known and 30-day EPSS is 0.9% (57th percentile), but defenders should treat it as actively exploited given the KEV listing and vendor confirmation.
What to do: Apply updated Qualcomm chipset firmware and GPU driver packages per the vendor security bulletin (shipped alongside fixes for the companion zero-days exploited via the Adreno GPU), and on Android fleets install OEM/Google security updates that include the Qualcomm fix, inventorying devices by chipset first. As a CISA KEV entry (added 2023-12-05), the required action is to apply vendor remediations or mitigations, or discontinue use of affected products if fixes are unavailable, with federal agencies bound by BOD 22-01 deadlines. Given reported targeted Android attacks chaining this bug for spyware delivery, review high-risk mobile endpoints for compromise indicators and prioritize patching for exposed or high-value users.
| Qualcomm 315 5G IoT Modem firmware | — |
| Qualcomm APQ8017 firmware | — |
| Qualcomm APQ8064AU firmware | — |
| Qualcomm AQT1000 firmware | — |
| Qualcomm AR8031 firmware | — |
| Qualcomm AR8035 firmware | — |
| Qualcomm C-V2X 9150 firmware | — |
| Qualcomm CSRA6620 firmware | — |
| Qualcomm CSRA6640 firmware | — |
| Qualcomm CSRB31024 firmware | — |
| Qualcomm FastConnect 6200 firmware | — |
| Qualcomm FastConnect 6700 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- 315 5g iot modem firmware, apq8017 firmware, apq8064au firmware, aqt1000 firmware, ar8031 firmware, ar8035 firmware, c-v2x 9150 firmware, csra6620 firmware, csra6640 firmware, csrb31024 firmware, fastconnect 6200 firmware, fastconnect 6700 firmware
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H