ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Qualcomm patches 3 actively exploited zero-days

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22071
Exploited Use-After-Free in Qualcomm Snapdragon and QCA Chipset Firmware

CVE-2022-22071 is a use-after-free (CWE-416) in the firmware of multiple Qualcomm Snapdragon SoCs and QCA connectivity chips, occurring when process shell memory is freed via an IOCTL munmap call while process initialization is still in progress. It is triggered locally by a low-privileged process during this initialization/memory-free sequence, so an attacker who can already run code on the device can exploit it. The result is high-impact memory corruption affecting confidentiality, integrity, and availability (CVSS 3.1: 7.8), consistent with local privilege escalation or full compromise of the affected chipset-based system. Any device built on the listed Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, or Voice & Music platforms is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-05, news reports describe Qualcomm patching three actively exploited zero-days in this disclosure, and ransomware use is unknown; EPSS is 0.5% and no public PoC is known.

Do: Apply the firmware fixes published in Qualcomm's security advisory via your device OEM or OS update channel, following CISA's KEV required action (patch per vendor instructions or discontinue use). Inventory devices using the listed chipsets (MSM8953/APQ8053, AR8031/AR8035, CSRA6620/CSRA6640, MDM9150, QCA6174A/6390/6391/6426/6436) and prioritize those where untrusted or low-privileged users can run code locally. Because the flaw is local-only, mitigate interim risk by restricting local code execution on affected devices; no public PoC or specific patched firmware version is available in the source data.

7.8<1% KEV
  • Qualcomm APQ8053 firmware
  • Qualcomm AR8031 firmware
  • Qualcomm AR8035 firmware
  • +9 more
massHundreds of millions of devices plausibly affected (chipsets deployed across smartphone, IoT, automotive, and embedded product lines)
CVE-2023-33028
+1 in the same advisory: …24855
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

NVD description · AI analysis pending
9.8<1%
  • qualcomm ar8035 firmware
  • qualcomm ar9380 firmware
  • qualcomm csr8811 firmware
  • +1 more
CVE-2023-28540
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

NVD description · AI analysis pending
7.5<1%
  • qualcomm 315 5g iot modem firmware
  • qualcomm aqt1000 firmware
  • qualcomm ar8035 firmware
  • +1 more
CVE-2023-33106
+2 in the same advisory: …33107 …33063
Out-of-Range Pointer Memory Corruption in Qualcomm KGSL GPU Driver (Actively Exploited)

CVE-2023-33106 is a memory-corruption flaw (use of out-of-range pointer offset, CWE-823/CWE-119) in Qualcomm's KGSL GPU kernel driver, which manages the Adreno graphics stack. It is triggered when a local, low-privileged process submits an AUX command containing a large list of sync points through the IOCTL_KGSL_GPU_AUX_COMMAND ioctl, causing out-of-bounds memory access. A successful attacker, typically a malicious app already running on the device, can corrupt kernel memory and escalate privileges, gaining the high confidentiality, integrity and availability impact reflected in its CVSS 7.8 local-attack score. Affected products include the listed Qualcomm components (FastConnect 6200/6700/6800/6900/7800, QAM8255P/QAM8295P/QAM8650P, Flight RB5 5G Platform, AR8035, CSRA6620/CSRA6640), and the vendor's advisory describes the flaw as spanning multiple chipsets. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, and public reporting indicates it was one of three Qualcomm zero-days actively exploited in targeted Android attacks alongside Adreno GPU issues; no public PoC is known.

Do: Install Android security updates or firmware from your device/OEM vendor that incorporate Qualcomm's fixes for this CVE, prioritizing devices and systems built on the listed chipsets, and check the Qualcomm security bulletin for the fixed firmware versions for each component. Because exploitation requires local code execution, avoid installing untrusted apps on unpatched devices as an interim mitigation. Organizations subject to BOD 22-01 must apply the vendor remediations per the KEV required action.

7.8<1% KEV
  • Qualcomm AR8035 firmware
  • Qualcomm CSRA6620 firmware
  • Qualcomm CSRA6640 firmware
  • +9 more
mass~hundreds of millions of devices (Qualcomm silicon across Android phones, automotive and IoT platforms); exact count unknown
CVE-2023-4211
Use-After-Free in Arm Mali GPU Kernel Driver (Actively Exploited)

CVE-2023-4211 is a use-after-free (CWE-416) in Arm's Mali GPU kernel drivers, covering the Midgard, Bifrost, Valhall and 5th Gen GPU Architecture product lines. A local, non-privileged attacker triggers the flaw by issuing improper GPU memory processing operations, causing the driver to access memory that has already been freed. Successful exploitation exposes already-freed kernel memory to the attacker (high confidentiality impact per the CVSS score), which on mobile devices can be chained into broader local information-gathering or privilege attacks. Any system running the affected Mali kernel drivers is exposed — in practice this is overwhelmingly Android smartphones, tablets and embedded devices whose SoCs integrate Mali GPUs. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-03, indicating confirmed in-the-wild exploitation; Arm has issued updated drivers, but patch availability varies by device vendor.

Do: Determine whether devices in your fleet use Mali GPUs and obtain updated Mali GPU kernel drivers from Arm via your device vendor's security updates (OEM/Android updates issued from October 2023 onward), since Arm fixes are distributed through device vendors rather than a standalone Arm patch channel. Until devices are patched, limit local, unprivileged access on affected systems to trusted users and monitor vendor bulletins for availability. Per the CISA KEV required action, apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

5.51% KEV
  • Arm Mali Midgard GPU kernel driver
  • Arm Mali Bifrost GPU kernel driver
  • Arm Mali Valhall GPU kernel driver
  • +1 more
mass≈1 billion+ devices (Mali GPUs are integrated in a very large share of Android smartphones, tablets and embedded devices)
Full article228 words · extracted from helpnetsecurity.com · click to collapse

Qualcomm has fixed three actively exploited vulnerabilities (CVE-2023-33106, CVE-2023-33107, CVE-2023-33063) in its Adreno GPU and Compute DSP drivers.

Qualcomm vulnerabilities exploited

Vulnerabilities exploited in Qualcomm GPU and DSP drivers

The US-based semiconductor company has been notified by Google Threat Analysis Group and Google Project Zero that CVE-2023-33106, CVE-2023-33107, CVE-2023-33063, and CVE-2022-22071 “may be under limited, targeted exploitation”.

CVE-2022-22071 is an older use-after-free vulnerability found in Automotive Android OS and patched in May 2022.

Additional information about the three zero-days will be shared in the December security bulletin, but the company has released patches for them. “OEMs have been notified with a strong recommendation to deploy security updates as soon as possible,” the company said.

In similar/related news, Arm has patched a zero-day vulnerability (CVE-2023-4211) in the kernel drivers for several Mali GPUs being exploited in targeted attacks, also spotted by Google TAG and Project Zero researchers.

Additional issues

In this month’s security bulletin, Qualcomm has disclosed additional seventeen vulnerabilities, of which three have been rated as critical:

  • CVE-2023-24855 – A memory corruption in Modem while processing security related configuration before AS Security Exchange.
  • CVE-2023-28540 – A cryptographic issue in Data Modem due to improper authentication during TLS handshake.
  • CVE-2023-33028 – A memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

There are no indications that these additional vulnerabilities have been exploited in the wild.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/10/04/qualcomm-vulnerabilities-exploited/