EXPOSURES › CVE-2023-33106
CVE-2023-33106
HIGH ⌖ ON CISA KEV · EXPLOITEDQualcomm chipsets contain a high-severity out-of-range pointer offset vulnerability in graphics memory handling that is actively exploited in the wild.
This vulnerability allows memory corruption via large sync point lists in GPU AUX commands, posing a significant risk to DIB systems relying on Qualcomm hardware for graphics processing. The fact that it is actively exploited in the wild and linked to ransomware campaigns means vendors must prioritize patching to prevent unauthorized access to sensitive systems.
Shame score — The vulnerability is actively exploited in the wild and linked to ransomware campaigns, indicating a failure to adequately secure widely used hardware components.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.