PT-2021-7006 · Qualcomm · Qualcomm Snapdragon Industrial Iot+4
Published
2021-11-01
·
Updated
2022-06-22
·
CVE-2021-35090
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon Auto versions (affected versions not specified)
Qualcomm Snapdragon Compute versions (affected versions not specified)
Qualcomm Snapdragon Connectivity versions (affected versions not specified)
Qualcomm Snapdragon Industrial IOT versions (affected versions not specified)
Qualcomm Snapdragon Mobile versions (affected versions not specified)
Description
The issue is related to a potential hypervisor memory corruption due to a Time-of-Check to Time-of-Use (TOC TOU) race condition when updating address mappings. This is also described as a vulnerability in the kernel of Qualcomm's embedded software, associated with synchronization errors when using a shared resource. Exploitation of this issue may allow an attacker to execute arbitrary code.
Recommendations
For Qualcomm Snapdragon Auto, update to a version that includes the fix for the synchronization errors.
For Qualcomm Snapdragon Compute, update to a version that includes the fix for the synchronization errors.
For Qualcomm Snapdragon Connectivity, update to a version that includes the fix for the synchronization errors.
For Qualcomm Snapdragon Industrial IOT, update to a version that includes the fix for the synchronization errors.
For Qualcomm Snapdragon Mobile, update to a version that includes the fix for the synchronization errors.
As a temporary workaround, consider restricting access to shared resources to minimize the risk of exploitation.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Mobile