7.8
CVSSv3

CVE-2023-21666

Published: 02/05/2023 Updated: 12/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm wcn3998_firmware -

qualcomm qca6390_firmware -

qualcomm wcn685x-5_firmware -

qualcomm wcn685x-1_firmware -

qualcomm flight_rb5_5g_platform_firmware -

qualcomm home_hub_100_platform_firmware -

qualcomm mdm9250_firmware -

qualcomm mdm9628_firmware -

qualcomm mdm9650_firmware -

qualcomm msm8108_firmware -

qualcomm msm8209_firmware -

qualcomm msm8608_firmware -

qualcomm msm8909w_firmware -

qualcomm qca6174_firmware -

qualcomm qca6174a_firmware -

qualcomm qca6310_firmware -

qualcomm qca6320_firmware -

qualcomm qca6335_firmware -

qualcomm qca6391_firmware -

qualcomm qca6420_firmware -

qualcomm qca6421_firmware -

qualcomm qca6426_firmware -

qualcomm qca6430_firmware -

qualcomm qca6431_firmware -

qualcomm qca6436_firmware -

qualcomm qca6564_firmware -

qualcomm qca6564a_firmware -

qualcomm qca6564au_firmware -

qualcomm qca6574_firmware -

qualcomm qca6574a_firmware -

qualcomm qca6574au_firmware -

qualcomm qca6595_firmware -

qualcomm qca6595au_firmware -

qualcomm qca6696_firmware -

qualcomm qca8337_firmware -

qualcomm qca9367_firmware -

qualcomm qca9377_firmware -

qualcomm qca9379_firmware -

qualcomm qcm2290_firmware -

qualcomm qcm4290_firmware -

qualcomm qcm6125_firmware -

qualcomm qcn9011_firmware -

qualcomm qcn9012_firmware -

qualcomm qcn9074_firmware -

qualcomm qcs2290_firmware -

qualcomm qcs410_firmware -

qualcomm qcs4290_firmware -

qualcomm qcs610_firmware -

qualcomm qcs6125_firmware -

qualcomm qcs8155_firmware -

qualcomm qcs8250_firmware -

qualcomm qrb5165m_firmware -

qualcomm qrb5165n_firmware -

qualcomm qsm8250_firmware -

qualcomm 8905_firmware -

qualcomm qm215_firmware -

qualcomm sda\\/sdm845_firmware -

qualcomm qrb5165_firmware -

qualcomm sa6145p_firmware -

qualcomm sa6150p_firmware -

qualcomm sa6155_firmware -

qualcomm sa6155p_firmware -

qualcomm sa8145p_firmware -

qualcomm sa8150p_firmware -

qualcomm sa8155_firmware -

qualcomm sa8155p_firmware -

qualcomm sa8195p_firmware -

qualcomm sd_675_firmware -

qualcomm sd626_firmware -

qualcomm sd660_firmware -

qualcomm sd670_firmware -

qualcomm sd675_firmware -

qualcomm sd730_firmware -

qualcomm sd835_firmware -

qualcomm sd855_firmware -

qualcomm sd865_5g_firmware -

qualcomm sdm429w_firmware -

qualcomm sdx20m_firmware -

qualcomm sdx55_firmware -

qualcomm sm4125_firmware -

qualcomm sm6250_firmware -

qualcomm sm6250p_firmware -

qualcomm sm7250p_firmware -

qualcomm apq8053-lite_firmware -

qualcomm apq5053-aa_firmware -

qualcomm snapdragon_1200_wearable_platform_firmware -

qualcomm snapdragon_208_processor_firmware -

qualcomm 8909_firmware -

qualcomm 8917_firmware -

qualcomm sdm429_firmware -

qualcomm sdm439_firmware -

qualcomm sdm450_firmware -

qualcomm sm4250-aa_firmware -

qualcomm 8953_firmware -

qualcomm 8953pro_firmware -

qualcomm snapdragon_632_mobile_platform_firmware -

qualcomm sdm660_firmware -

qualcomm sm6115_firmware -

qualcomm sm6125_firmware -

qualcomm sdm670_firmware -

qualcomm sm6150_firmware -

qualcomm sm6150-ac_firmware -

qualcomm sm6225_firmware -

qualcomm sm6225-ad_firmware -

qualcomm sm6350_firmware -

qualcomm sdm710_firmware -

qualcomm sm7125_firmware -

qualcomm sm7150-aa_firmware -

qualcomm sm7150-ab_firmware -

qualcomm sm7150-ac_firmware -

qualcomm sm7225_firmware -

qualcomm sm7250-aa_firmware -

qualcomm sm7250-ab_firmware -

qualcomm sm7250-ac_firmware -

qualcomm snapdragon_820_automotive_platform_firmware -

qualcomm 8998_firmware -

qualcomm sdm845_firmware -

qualcomm sm8250-ab_firmware -

qualcomm sm8250-ac_firmware -

qualcomm snapdragon_auto_5g_modem-rf_firmware -

qualcomm snapdragon_wear_2100_platform_firmware -

qualcomm snapdragon_wear_2500_platform_firmware -

qualcomm snapdragon_wear_3100_platform_firmware -

qualcomm snapdragon_wear_4100\\+_platform_firmware -

qualcomm snapdragon_x20_lte_modem_firmware -

qualcomm snapdragon_x24_lte_modem_firmware -

qualcomm snapdragon_x5_lte_modem_firmware -

qualcomm snapdragon_x50_5g_modem-rf_system_firmware -

qualcomm snapdragon_x55_5g_modem-rf_system_firmware -

qualcomm snapdragon_xr1_platform_firmware -

qualcomm snapdragon_xr2_5g_platform_firmware -

qualcomm snapdragon_xr2\\+_gen_1_platform_firmware -

qualcomm snapdragon_auto_4g_modem_firmware -

qualcomm sxr1120_firmware -

qualcomm sxr2130_firmware -

qualcomm apq8053-aa_firmware -

qualcomm apq8053-ac_firmware -

qualcomm qcs605_firmware -

qualcomm wcd9326_firmware -

qualcomm wcd9330_firmware -

qualcomm wcd9335_firmware -

qualcomm wcd9340_firmware -

qualcomm wcd9341_firmware -

qualcomm wcd9370_firmware -

qualcomm wcd9371_firmware -

qualcomm wcd9375_firmware -

qualcomm wcd9380_firmware -

qualcomm wcd9385_firmware -

qualcomm wcn3610_firmware -

qualcomm wcn3615_firmware -

qualcomm wcn3620_firmware -

qualcomm wcn3660_firmware -

qualcomm wcn3660b_firmware -

qualcomm wcn3680_firmware -

qualcomm wcn3680b_firmware -

qualcomm wcn3910_firmware -

qualcomm wcn3950_firmware -

qualcomm wcn3980_firmware -

qualcomm wcn3988_firmware -

qualcomm wcn3990_firmware -

qualcomm wcn3999_firmware -

qualcomm wsa8810_firmware -

qualcomm wsa8815_firmware -

qualcomm wsa8830_firmware -

qualcomm wsa8835_firmware -

Exploits

On Qualcomm Adreno/KGSL builds where CONFIG_QCOM_KGSL_USE_SHMEM is not set (or on older KGSL versions without CONFIG_QCOM_KGSL_USE_SHMEM), KGSL allocates GPU-shared memory from its own page pool Pages from this pool are inserted into VMAs that don't have any weird flags like VM_PFNMAP set, which means userspace can grab extra references to these p ...