Skip to content
COOEY

EXPOSURES › CVE-2021-1906

CVE-2021-1906

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-1906 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Qualcomm chipsets had an unpatched error-handling flaw that caused GPU allocation failures and was actively exploited in the wild.

Improper handling of address deregistration on failure in Qualcomm chipsets led to GPU address allocation failures, a known vulnerability that remained unpatched long enough to be added to CISA's KEV catalog. DIB organizations must ensure their hardware supply chains are rigorously vetted for known, unpatched flaws that can degrade system stability and create exploitable conditions. The failure highlights the risk of relying on hardware components with known, unpatched vulnerabilities that are actively exploited in the wild.

Shame score — A known, unpatched vulnerability in widely deployed hardware was actively exploited in the wild, demonstrating severe negligence in patch management and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Qualcomm's GPU driver flaws were noted as giving hackers full control, indicating severe fallout despite limited targeted exploitation reports.
The Hacker News ↗ severe-fallout -0.80
Severe - Unisoc exploit chain shows similar severe fallout for chipset vendors.
"Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker."
rottenwifi.com ↗ severe-fallout -0.70
Negative - flaws gave hackers full control.
"4 vulnerabilities under attack gave hackers full control of some Android devices (2021). The 4 vulnerabilities under attack were CVE-2021-1905, CVE-2021-1906, CVE-2021-28663, and CVE-2021-28664, GPU-driver flaws affecting some Qualcomm Adreno and Arm Mali Android devices in 2021."
cooey ↗ severe-fallout -0.50
Neutral technical disclosure without condemnation.
"Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure."
sam.gov ↗ severe-fallout +0.00
Irrelevant - SAM.gov procurement data.
www.comparitech.com ↗ severe-fallout +0.00
Irrelevant - Ransomware map.
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Irrelevant - Cisco advisory unrelated to Qualcomm.
www.cvefind.com ↗ severe-fallout +0.00
Irrelevant - CVE database listing.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.