ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Qualcomm flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22071
Exploited Use-After-Free in Qualcomm Snapdragon and QCA Chipset Firmware

CVE-2022-22071 is a use-after-free (CWE-416) in the firmware of multiple Qualcomm Snapdragon SoCs and QCA connectivity chips, occurring when process shell memory is freed via an IOCTL munmap call while process initialization is still in progress. It is triggered locally by a low-privileged process during this initialization/memory-free sequence, so an attacker who can already run code on the device can exploit it. The result is high-impact memory corruption affecting confidentiality, integrity, and availability (CVSS 3.1: 7.8), consistent with local privilege escalation or full compromise of the affected chipset-based system. Any device built on the listed Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, or Voice & Music platforms is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-05, news reports describe Qualcomm patching three actively exploited zero-days in this disclosure, and ransomware use is unknown; EPSS is 0.5% and no public PoC is known.

Do: Apply the firmware fixes published in Qualcomm's security advisory via your device OEM or OS update channel, following CISA's KEV required action (patch per vendor instructions or discontinue use). Inventory devices using the listed chipsets (MSM8953/APQ8053, AR8031/AR8035, CSRA6620/CSRA6640, MDM9150, QCA6174A/6390/6391/6426/6436) and prioritize those where untrusted or low-privileged users can run code locally. Because the flaw is local-only, mitigate interim risk by restricting local code execution on affected devices; no public PoC or specific patched firmware version is available in the source data.

7.8<1% KEV
  • Qualcomm APQ8053 firmware
  • Qualcomm AR8031 firmware
  • Qualcomm AR8035 firmware
  • +9 more
massHundreds of millions of devices plausibly affected (chipsets deployed across smartphone, IoT, automotive, and embedded product lines)
CVE-2023-33106
+2 in the same advisory: …33107 …33063
Out-of-Range Pointer Memory Corruption in Qualcomm KGSL GPU Driver (Actively Exploited)

CVE-2023-33106 is a memory-corruption flaw (use of out-of-range pointer offset, CWE-823/CWE-119) in Qualcomm's KGSL GPU kernel driver, which manages the Adreno graphics stack. It is triggered when a local, low-privileged process submits an AUX command containing a large list of sync points through the IOCTL_KGSL_GPU_AUX_COMMAND ioctl, causing out-of-bounds memory access. A successful attacker, typically a malicious app already running on the device, can corrupt kernel memory and escalate privileges, gaining the high confidentiality, integrity and availability impact reflected in its CVSS 7.8 local-attack score. Affected products include the listed Qualcomm components (FastConnect 6200/6700/6800/6900/7800, QAM8255P/QAM8295P/QAM8650P, Flight RB5 5G Platform, AR8035, CSRA6620/CSRA6640), and the vendor's advisory describes the flaw as spanning multiple chipsets. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, and public reporting indicates it was one of three Qualcomm zero-days actively exploited in targeted Android attacks alongside Adreno GPU issues; no public PoC is known.

Do: Install Android security updates or firmware from your device/OEM vendor that incorporate Qualcomm's fixes for this CVE, prioritizing devices and systems built on the listed chipsets, and check the Qualcomm security bulletin for the fixed firmware versions for each component. Because exploitation requires local code execution, avoid installing untrusted apps on unpatched devices as an interim mitigation. Organizations subject to BOD 22-01 must apply the vendor remediations per the KEV required action.

7.8<1% KEV
  • Qualcomm AR8035 firmware
  • Qualcomm CSRA6620 firmware
  • Qualcomm CSRA6640 firmware
  • +9 more
mass~hundreds of millions of devices (Qualcomm silicon across Android phones, automotive and IoT platforms); exact count unknown
Full article265 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 06, 2023

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds four Qualcomm vulnerabilities to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualcomm vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

Below is the list of the issues added to the catalog:

  • CVE-2023-33106 Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
  • CVE-2023-33063 Qualcomm Multiple Chipsets Use-After-Free Vulnerability
  • CVE-2023-33107 Qualcomm Multiple Chipsets Integer Overflow Vulnerability
  • CVE-2022-22071 Qualcomm Multiple Chipsets Use-After-Free Vulnerability

The vendor addressed the flaws CVE-2023-33106, CVE-2023-33107, and CVE-2023-33063 in October 2023. The company also warned that three of the zero-day vulnerabilities were actively exploited in attacks in the wild. CVE-2022-22071 was included in our May 2022 public bulletin.

Google Threat Analysis Group and Google Project Zero first reported that the CVE-2023-33106, CVE-2023-33107, CVE-2022-22071 and CVE-2023-33063 were actively exploited in targeted attacks.

Google Threat Analysis Group and Google Project Zero experts focus on attacks carried out by nation-state actors or surveillance firms, this means that one of these threat actors may be behind the exploitation of the Qualcomm flaws.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix these vulnerabilities by December 26, 2023.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/155340/security/cisa-qualcomm-flaws-known-exploited-vulnerabilities-catalog.html