Skip to content
COOEY

EXPOSURES › CVE-2023-33106

CVE-2023-33106

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-12-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-33106 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedransomware

Qualcomm chipsets contain a high-severity out-of-range pointer offset vulnerability in graphics memory handling that is actively exploited in the wild.

This vulnerability allows memory corruption via large sync point lists in GPU AUX commands, posing a significant risk to DIB systems relying on Qualcomm hardware for graphics processing. The fact that it is actively exploited in the wild and linked to ransomware campaigns means vendors must prioritize patching to prevent unauthorized access to sensitive systems.

Shame score — The vulnerability is actively exploited in the wild and linked to ransomware campaigns, indicating a failure to adequately secure widely used hardware components.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.