EXPOSURES › CVE-2021-1906
CVE-2021-1906
HIGH ⌖ ON CISA KEV · EXPLOITEDQualcomm chipsets had an unpatched error-handling flaw that caused GPU allocation failures and was actively exploited in the wild.
Improper handling of address deregistration on failure in Qualcomm chipsets led to GPU address allocation failures, a known vulnerability that remained unpatched long enough to be added to CISA's KEV catalog. DIB organizations must ensure their hardware supply chains are rigorously vetted for known, unpatched flaws that can degrade system stability and create exploitable conditions. The failure highlights the risk of relying on hardware components with known, unpatched vulnerabilities that are actively exploited in the wild.
Shame score — A known, unpatched vulnerability in widely deployed hardware was actively exploited in the wild, demonstrating severe negligence in patch management and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.
"Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker."
"4 vulnerabilities under attack gave hackers full control of some Android devices (2021). The 4 vulnerabilities under attack were CVE-2021-1905, CVE-2021-1906, CVE-2021-28663, and CVE-2021-28664, GPU-driver flaws affecting some Qualcomm Adreno and Arm Mali Android devices in 2021."
"Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure."