PT-2022-9997 · Qualcomm · Snapdragon Wearables+6

Published

2022-06-14

·

Updated

2023-04-19

·

CVE-2021-30334

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon versions (affected versions not specified)
Description The issue is related to a possible use after free due to the lack of a null check of DRM file status after the file structure is freed. This affects various Qualcomm Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, and Snapdragon Wearables.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2021-30334

Affected Products

Snapdragon Auto
Snapdragon Compute
Snapdragon Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Voice & Music
Snapdragon Wearables