CVE-2021-1906KEV · OVERDUE

Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

Medium · published May 7, 2021

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 6.2. It is confirmed in active exploitation. It sits in the 42.2th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
6.2
EPSS
1%
Percentile
42.2
In the wild
Confirmed
What it is

⚠️ A failure in deregistration can lead to allocation headaches! An improper handling of address deregistration in Snapdragon components could cause new GPU address allocations to go belly-up. 🔧 Think of it like a restaurant that fails to remove a customer's reservation after they've left. The next patrons arrive, only to find no tables available because the restaurant didn't clear the names off the list. This could lead to performance issues or even crashes in devices utilizing any Snapdragon component, impacting everything from mobile phones to industrial IoT systems. If a device can't allocate the resources it needs, it might freeze or fail completely, leaving users frustrated.

Put simply

Think of it like a restaurant that fails to remove a customer's reservation after they've left. The next patrons arrive, only to find no tables available because the restaurant didn't clear the names off the list. The vulnerability arises from improper handling of address deregistration failures on Snapdragon platforms, which can result in the inability to allocate new GPU addresses. This issue affects a variety of Snapdragon components, making it broadly impactful.

What to do

This could lead to performance issues or even crashes in devices utilizing any Snapdragon component, impacting everything from mobile phones to industrial IoT systems. If a device can't allocate the resources it needs, it might freeze or fail completely, leaving users frustrated. To mitigate this, ensure all Snapdragon devices are updated to the latest firmware and patches provided by Qualcomm. It's crucial to monitor device behavior and report any irregularities that may arise during allocation processes. You've got this! Stay proactive with updates and keep your devices running smoothly. 🛡️

The record
Technical detail
CVSS v3.1
6.2 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00520 · 42.2th percentile
Published
2021-05-07T09:10Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 07 MAY 09:10Z
    Improper handling of address deregistration on failure can lead to new GPU address allocation failure
    cvelistv5