PT-2021-7062 · Qualcomm · Qualcomm Snapdragon Industrial Iot+5

Published

2021-11-01

·

Updated

2021-11-15

·

CVE-2021-1921

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto versions prior to the fixed version Qualcomm Snapdragon Compute versions prior to the fixed version Qualcomm Snapdragon Connectivity versions prior to the fixed version Qualcomm Snapdragon Consumer IOT versions prior to the fixed version Qualcomm Snapdragon Industrial IOT versions prior to the fixed version Qualcomm Snapdragon Mobile versions prior to the fixed version
Description The issue is caused by a race condition in the firmware of Qualcomm's embedded platforms. It may lead to memory corruption due to improper handling of hypervisor unmap operations for concurrent memory operations. This could impact the confidentiality, integrity, and availability of protected information.
Recommendations For Qualcomm Snapdragon Auto, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Compute, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Connectivity, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Consumer IOT, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Industrial IOT, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Mobile, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to concurrent memory operations until a patch is available.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03129
CVE-2021-1921

Affected Products

Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Mobile