ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Arm and Qualcomm Hit by Multiple Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22071
Exploited Use-After-Free in Qualcomm Snapdragon and QCA Chipset Firmware

CVE-2022-22071 is a use-after-free (CWE-416) in the firmware of multiple Qualcomm Snapdragon SoCs and QCA connectivity chips, occurring when process shell memory is freed via an IOCTL munmap call while process initialization is still in progress. It is triggered locally by a low-privileged process during this initialization/memory-free sequence, so an attacker who can already run code on the device can exploit it. The result is high-impact memory corruption affecting confidentiality, integrity, and availability (CVSS 3.1: 7.8), consistent with local privilege escalation or full compromise of the affected chipset-based system. Any device built on the listed Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, or Voice & Music platforms is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-05, news reports describe Qualcomm patching three actively exploited zero-days in this disclosure, and ransomware use is unknown; EPSS is 0.5% and no public PoC is known.

Do: Apply the firmware fixes published in Qualcomm's security advisory via your device OEM or OS update channel, following CISA's KEV required action (patch per vendor instructions or discontinue use). Inventory devices using the listed chipsets (MSM8953/APQ8053, AR8031/AR8035, CSRA6620/CSRA6640, MDM9150, QCA6174A/6390/6391/6426/6436) and prioritize those where untrusted or low-privileged users can run code locally. Because the flaw is local-only, mitigate interim risk by restricting local code execution on affected devices; no public PoC or specific patched firmware version is available in the source data.

7.8<1% KEV
  • Qualcomm APQ8053 firmware
  • Qualcomm AR8031 firmware
  • Qualcomm AR8035 firmware
  • +9 more
massHundreds of millions of devices plausibly affected (chipsets deployed across smartphone, IoT, automotive, and embedded product lines)
CVE-2023-33028
+1 in the same advisory: …24855
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

NVD description · AI analysis pending
9.8<1%
  • qualcomm ar8035 firmware
  • qualcomm ar9380 firmware
  • qualcomm csr8811 firmware
  • +1 more
CVE-2023-33106
+2 in the same advisory: …33107 …33063
Out-of-Range Pointer Memory Corruption in Qualcomm KGSL GPU Driver (Actively Exploited)

CVE-2023-33106 is a memory-corruption flaw (use of out-of-range pointer offset, CWE-823/CWE-119) in Qualcomm's KGSL GPU kernel driver, which manages the Adreno graphics stack. It is triggered when a local, low-privileged process submits an AUX command containing a large list of sync points through the IOCTL_KGSL_GPU_AUX_COMMAND ioctl, causing out-of-bounds memory access. A successful attacker, typically a malicious app already running on the device, can corrupt kernel memory and escalate privileges, gaining the high confidentiality, integrity and availability impact reflected in its CVSS 7.8 local-attack score. Affected products include the listed Qualcomm components (FastConnect 6200/6700/6800/6900/7800, QAM8255P/QAM8295P/QAM8650P, Flight RB5 5G Platform, AR8035, CSRA6620/CSRA6640), and the vendor's advisory describes the flaw as spanning multiple chipsets. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-05, and public reporting indicates it was one of three Qualcomm zero-days actively exploited in targeted Android attacks alongside Adreno GPU issues; no public PoC is known.

Do: Install Android security updates or firmware from your device/OEM vendor that incorporate Qualcomm's fixes for this CVE, prioritizing devices and systems built on the listed chipsets, and check the Qualcomm security bulletin for the fixed firmware versions for each component. Because exploitation requires local code execution, avoid installing untrusted apps on unpatched devices as an interim mitigation. Organizations subject to BOD 22-01 must apply the vendor remediations per the KEV required action.

7.8<1% KEV
  • Qualcomm AR8035 firmware
  • Qualcomm CSRA6620 firmware
  • Qualcomm CSRA6640 firmware
  • +9 more
mass~hundreds of millions of devices (Qualcomm silicon across Android phones, automotive and IoT platforms); exact count unknown
CVE-2023-33200
A local non-privileged user can make improper GPU processing operations to exploit a software race condition.

A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.

NVD description · AI analysis pending
4.7<1%
  • arm bifrost gpu kernel driver
  • arm mali gpu kernel driver
  • arm valhall gpu kernel driver
CVE-2023-34970
A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condit

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

NVD description · AI analysis pending
4.7<1%
  • arm mali gpu kernel driver
  • arm valhall gpu kernel driver
CVE-2023-4211
Use-After-Free in Arm Mali GPU Kernel Driver (Actively Exploited)

CVE-2023-4211 is a use-after-free (CWE-416) in Arm's Mali GPU kernel drivers, covering the Midgard, Bifrost, Valhall and 5th Gen GPU Architecture product lines. A local, non-privileged attacker triggers the flaw by issuing improper GPU memory processing operations, causing the driver to access memory that has already been freed. Successful exploitation exposes already-freed kernel memory to the attacker (high confidentiality impact per the CVSS score), which on mobile devices can be chained into broader local information-gathering or privilege attacks. Any system running the affected Mali kernel drivers is exposed — in practice this is overwhelmingly Android smartphones, tablets and embedded devices whose SoCs integrate Mali GPUs. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-03, indicating confirmed in-the-wild exploitation; Arm has issued updated drivers, but patch availability varies by device vendor.

Do: Determine whether devices in your fleet use Mali GPUs and obtain updated Mali GPU kernel drivers from Arm via your device vendor's security updates (OEM/Android updates issued from October 2023 onward), since Arm fixes are distributed through device vendors rather than a standalone Arm patch channel. Until devices are patched, limit local, unprivileged access on affected systems to trusted users and monitor vendor bulletins for availability. Per the CISA KEV required action, apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

5.51% KEV
  • Arm Mali Midgard GPU kernel driver
  • Arm Mali Bifrost GPU kernel driver
  • Arm Mali Valhall GPU kernel driver
  • +1 more
mass≈1 billion+ devices (Mali GPUs are integrated in a very large share of Android smartphones, tablets and embedded devices)
Full article341 words · extracted from infosecurity-magazine.com · click to collapse

Qualcomm and Arm have been forced to release security updates to patch several zero-day vulnerabilities exploited in recent targeted attacks against their chips.

Qualcomm said on Tuesday it was informed by the Google Threat Analysis Group (TAG) and Project Zero team that CVE-2023-33106, CVE-2023-33107, CVE-2023-33063 and CVE-2022-22071 “may be under limited, targeted exploitation.”

The first three are previously unseen vulnerabilities, while the latter was fixed in Qualcomm’s May 2022 public bulletin. Although details of the zero-day bugs won’t be shared by the chip giant until its December bulletin, updates have been issued.

“Patches for the issues affecting Adreno GPU and Compute DSP drivers have been made available, and OEMs have been notified with a strong recommendation to deploy security updates as soon as possible,” it said. 

“Please contact your device manufacturer for more information on the patch status about specific devices.”

Qualcomm also patched three critical and 13 high-severity vulnerabilities in its October bulletin.

Of these, CVE-2023-33028 and CVE-2023-24855 are the most serious, with both given a CVSS score of 9.8. The former is a memory corruption issue in the WLAN firmware while the latter is a memory corruption issue in the modem.

Arm was also informed by Google TAG and Project Zero this week of a new zero-day vulnerability CVE-2023-4211 which it claimed is being actively exploited in targeted attacks.

“A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory,” the chip designer said in an advisory.

Users are recommended to upgrade if affected. The issue is fixed in Bifrost, Valhall and Arm 5th Gen GPU Architecture Kernel Driver r43p0.

The bug also affects all versions of the Midgard GPU kernel driver from r12p0 – r32p0, and Arm urged customers of those chip designs to contact its support team.

In the same bulletin, Arm revealed new vulnerabilities CVE-2023-33200 and CVE-2023-34970, which also affect various flavors of its Mali GPU kernel driver and allow “improper GPU memory processing operations.”

Read more on chip flaws: Google Exposes 18 Zero-Day Flaws in Samsung Exynos Chips 

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/arm-qualcomm-hit-multiple-zeroday/