PT-2021-7006 · Qualcomm · Qualcomm Snapdragon Industrial Iot+4

Published

2021-11-01

·

Updated

2022-06-22

·

CVE-2021-35090

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto versions (affected versions not specified) Qualcomm Snapdragon Compute versions (affected versions not specified) Qualcomm Snapdragon Connectivity versions (affected versions not specified) Qualcomm Snapdragon Industrial IOT versions (affected versions not specified) Qualcomm Snapdragon Mobile versions (affected versions not specified)
Description The issue is related to a potential hypervisor memory corruption due to a Time-of-Check to Time-of-Use (TOC TOU) race condition when updating address mappings. This is also described as a vulnerability in the kernel of Qualcomm's embedded software, associated with synchronization errors when using a shared resource. Exploitation of this issue may allow an attacker to execute arbitrary code.
Recommendations For Qualcomm Snapdragon Auto, update to a version that includes the fix for the synchronization errors. For Qualcomm Snapdragon Compute, update to a version that includes the fix for the synchronization errors. For Qualcomm Snapdragon Connectivity, update to a version that includes the fix for the synchronization errors. For Qualcomm Snapdragon Industrial IOT, update to a version that includes the fix for the synchronization errors. For Qualcomm Snapdragon Mobile, update to a version that includes the fix for the synchronization errors. As a temporary workaround, consider restricting access to shared resources to minimize the risk of exploitation.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02924
CVE-2021-35090

Affected Products

Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Mobile