EXPOSURES › CVE-2023-33107
CVE-2023-33107
HIGH ⌖ ON CISA KEV · EXPLOITEDQualcomm chipsets contain an integer overflow vulnerability in Graphics Linux that allows memory corruption during IOCTL calls.
This integer overflow vulnerability in Qualcomm chipsets enables memory corruption during shared virtual memory region assignment via IOCTL calls, posing a significant risk to DIB organizations relying on Qualcomm hardware for secure systems. The vulnerability is actively exploited in the KEV list, indicating widespread real-world impact and requiring immediate vendor patching and system isolation to prevent potential remote code execution.
Shame score — Active exploitation in KEV list indicates widespread impact and requires immediate remediation to prevent potential remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.