CVE-2021-1968
Qualcomm NPU Use-After-Free / Information Leak
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Una comprobación inapropiada de la dirección del búfer del kernel mientras se copia la información en el búfer del usuario puede conllevar a una exposición de la información de la memoria del kernel al espacio del usuario en Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-12-08 CVE Reserved
- 2021-10-20 CVE Published
- 2023-05-13 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/172856/Qualcomm-NPU-Use-After-Free-Information-Leak.html |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qualcomm.com/company/product-security/bulletins/october-2021-bulletin | 2023-06-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qualcomm Search vendor "Qualcomm" | Aqt1000 Firmware Search vendor "Qualcomm" for product "Aqt1000 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Aqt1000 Search vendor "Qualcomm" for product "Aqt1000" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Ar8031 Firmware Search vendor "Qualcomm" for product "Ar8031 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Ar8031 Search vendor "Qualcomm" for product "Ar8031" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Ar8035 Firmware Search vendor "Qualcomm" for product "Ar8035 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Ar8035 Search vendor "Qualcomm" for product "Ar8035" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Csra6620 Firmware Search vendor "Qualcomm" for product "Csra6620 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Csra6620 Search vendor "Qualcomm" for product "Csra6620" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Csra6640 Firmware Search vendor "Qualcomm" for product "Csra6640 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Csra6640 Search vendor "Qualcomm" for product "Csra6640" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Fsm10055 Firmware Search vendor "Qualcomm" for product "Fsm10055 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Fsm10055 Search vendor "Qualcomm" for product "Fsm10055" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Fsm10056 Firmware Search vendor "Qualcomm" for product "Fsm10056 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Fsm10056 Search vendor "Qualcomm" for product "Fsm10056" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9150 Firmware Search vendor "Qualcomm" for product "Mdm9150 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9150 Search vendor "Qualcomm" for product "Mdm9150" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6391 Firmware Search vendor "Qualcomm" for product "Qca6391 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6391 Search vendor "Qualcomm" for product "Qca6391" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6420 Firmware Search vendor "Qualcomm" for product "Qca6420 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6420 Search vendor "Qualcomm" for product "Qca6420" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6430 Firmware Search vendor "Qualcomm" for product "Qca6430 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6430 Search vendor "Qualcomm" for product "Qca6430" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6574 Firmware Search vendor "Qualcomm" for product "Qca6574 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6574 Search vendor "Qualcomm" for product "Qca6574" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6574a Firmware Search vendor "Qualcomm" for product "Qca6574a Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6574a Search vendor "Qualcomm" for product "Qca6574a" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6574au Firmware Search vendor "Qualcomm" for product "Qca6574au Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6574au Search vendor "Qualcomm" for product "Qca6574au" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6584au Firmware Search vendor "Qualcomm" for product "Qca6584au Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6584au Search vendor "Qualcomm" for product "Qca6584au" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6595 Firmware Search vendor "Qualcomm" for product "Qca6595 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6595 Search vendor "Qualcomm" for product "Qca6595" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6595au Firmware Search vendor "Qualcomm" for product "Qca6595au Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6595au Search vendor "Qualcomm" for product "Qca6595au" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6696 Firmware Search vendor "Qualcomm" for product "Qca6696 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6696 Search vendor "Qualcomm" for product "Qca6696" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca8337 Firmware Search vendor "Qualcomm" for product "Qca8337 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca8337 Search vendor "Qualcomm" for product "Qca8337" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qcm6125 Firmware Search vendor "Qualcomm" for product "Qcm6125 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qcm6125 Search vendor "Qualcomm" for product "Qcm6125" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qcs405 Firmware Search vendor "Qualcomm" for product "Qcs405 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qcs405 Search vendor "Qualcomm" for product "Qcs405" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qcs410 Firmware Search vendor "Qualcomm" for product "Qcs410 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qcs410 Search vendor "Qualcomm" for product "Qcs410" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qcs610 Firmware Search vendor "Qualcomm" for product "Qcs610 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qcs610 Search vendor "Qualcomm" for product "Qcs610" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qcs6125 Firmware Search vendor "Qualcomm" for product "Qcs6125 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qcs6125 Search vendor "Qualcomm" for product "Qcs6125" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa6145p Firmware Search vendor "Qualcomm" for product "Sa6145p Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa6145p Search vendor "Qualcomm" for product "Sa6145p" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa6150p Firmware Search vendor "Qualcomm" for product "Sa6150p Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa6150p Search vendor "Qualcomm" for product "Sa6150p" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa6155 Firmware Search vendor "Qualcomm" for product "Sa6155 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa6155 Search vendor "Qualcomm" for product "Sa6155" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa6155p Firmware Search vendor "Qualcomm" for product "Sa6155p Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa6155p Search vendor "Qualcomm" for product "Sa6155p" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa8145p Firmware Search vendor "Qualcomm" for product "Sa8145p Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa8145p Search vendor "Qualcomm" for product "Sa8145p" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa8150p Firmware Search vendor "Qualcomm" for product "Sa8150p Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa8150p Search vendor "Qualcomm" for product "Sa8150p" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa8155 Firmware Search vendor "Qualcomm" for product "Sa8155 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa8155 Search vendor "Qualcomm" for product "Sa8155" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa8155p Firmware Search vendor "Qualcomm" for product "Sa8155p Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa8155p Search vendor "Qualcomm" for product "Sa8155p" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sa8195p Firmware Search vendor "Qualcomm" for product "Sa8195p Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sa8195p Search vendor "Qualcomm" for product "Sa8195p" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 675 Firmware Search vendor "Qualcomm" for product "Sd 675 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 675 Search vendor "Qualcomm" for product "Sd 675" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 8c Firmware Search vendor "Qualcomm" for product "Sd 8c Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 8c Search vendor "Qualcomm" for product "Sd 8c" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 8cx Firmware Search vendor "Qualcomm" for product "Sd 8cx Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 8cx Search vendor "Qualcomm" for product "Sd 8cx" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd665 Firmware Search vendor "Qualcomm" for product "Sd665 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd665 Search vendor "Qualcomm" for product "Sd665" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd675 Firmware Search vendor "Qualcomm" for product "Sd675 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd675 Search vendor "Qualcomm" for product "Sd675" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd678 Firmware Search vendor "Qualcomm" for product "Sd678 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd678 Search vendor "Qualcomm" for product "Sd678" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd720g Firmware Search vendor "Qualcomm" for product "Sd720g Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd720g Search vendor "Qualcomm" for product "Sd720g" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd855 Firmware Search vendor "Qualcomm" for product "Sd855 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd855 Search vendor "Qualcomm" for product "Sd855" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sda429w Firmware Search vendor "Qualcomm" for product "Sda429w Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sda429w Search vendor "Qualcomm" for product "Sda429w" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdx55 Firmware Search vendor "Qualcomm" for product "Sdx55 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdx55 Search vendor "Qualcomm" for product "Sdx55" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdx55m Firmware Search vendor "Qualcomm" for product "Sdx55m Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdx55m Search vendor "Qualcomm" for product "Sdx55m" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sm6250 Firmware Search vendor "Qualcomm" for product "Sm6250 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sm6250 Search vendor "Qualcomm" for product "Sm6250" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcd9335 Firmware Search vendor "Qualcomm" for product "Wcd9335 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcd9335 Search vendor "Qualcomm" for product "Wcd9335" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcd9340 Firmware Search vendor "Qualcomm" for product "Wcd9340 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcd9340 Search vendor "Qualcomm" for product "Wcd9340" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcd9341 Firmware Search vendor "Qualcomm" for product "Wcd9341 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcd9341 Search vendor "Qualcomm" for product "Wcd9341" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcd9370 Firmware Search vendor "Qualcomm" for product "Wcd9370 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcd9370 Search vendor "Qualcomm" for product "Wcd9370" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcd9375 Firmware Search vendor "Qualcomm" for product "Wcd9375 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcd9375 Search vendor "Qualcomm" for product "Wcd9375" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcd9380 Firmware Search vendor "Qualcomm" for product "Wcd9380 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcd9380 Search vendor "Qualcomm" for product "Wcd9380" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3610 Firmware Search vendor "Qualcomm" for product "Wcn3610 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3610 Search vendor "Qualcomm" for product "Wcn3610" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3620 Firmware Search vendor "Qualcomm" for product "Wcn3620 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3620 Search vendor "Qualcomm" for product "Wcn3620" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3660b Firmware Search vendor "Qualcomm" for product "Wcn3660b Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3660b Search vendor "Qualcomm" for product "Wcn3660b" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3950 Firmware Search vendor "Qualcomm" for product "Wcn3950 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3950 Search vendor "Qualcomm" for product "Wcn3950" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3980 Firmware Search vendor "Qualcomm" for product "Wcn3980 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3980 Search vendor "Qualcomm" for product "Wcn3980" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3988 Firmware Search vendor "Qualcomm" for product "Wcn3988 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3988 Search vendor "Qualcomm" for product "Wcn3988" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3991 Firmware Search vendor "Qualcomm" for product "Wcn3991 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3991 Search vendor "Qualcomm" for product "Wcn3991" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3998 Firmware Search vendor "Qualcomm" for product "Wcn3998 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3998 Search vendor "Qualcomm" for product "Wcn3998" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wcn3999 Firmware Search vendor "Qualcomm" for product "Wcn3999 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wcn3999 Search vendor "Qualcomm" for product "Wcn3999" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wsa8810 Firmware Search vendor "Qualcomm" for product "Wsa8810 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wsa8810 Search vendor "Qualcomm" for product "Wsa8810" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Wsa8815 Firmware Search vendor "Qualcomm" for product "Wsa8815 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Wsa8815 Search vendor "Qualcomm" for product "Wsa8815" | - | - |
Safe
|