CVE-2023-33106

Confirmed PUBLISHED

Use of Out-of-range Pointer Offset in Graphics

Qualcomm, Inc. · Snapdragon
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.4 High

At a Glance

Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

cisa
CVE Published
Dec 05, 2023
Exploitation Reported
Dec 05, 2023
CVSS
8.4 High
EPSS
Low complexity No user interaction Unauthenticated

Affected Versions

291 version rows · page 6 of 12

Vendor Product Version Status
qualcomm
wcn3950_firmware

0 to <= *

Affected
qualcomm
wcn3980_firmware

0 to <= *

Affected
qualcomm
wcn3988_firmware

0 to <= *

Affected
qualcomm
wcn3990_firmware

0 to <= *

Affected
qualcomm
wcn6740_firmware

0 to <= *

Affected
qualcomm
wsa8810_firmware

0 to <= *

Affected
qualcomm
wsa8815_firmware

0 to <= *

Affected
qualcomm
wsa8830_firmware

0 to <= *

Affected
qualcomm
wsa8832_firmware

0 to <= *

Affected
qualcomm
wsa8835_firmware

0 to <= *

Affected
qualcomm
wsa8840_firmware

0 to <= *

Affected
qualcomm
wsa8845_firmware

0 to <= *

Affected
qualcomm
wsa8845h_firmware

0 to <= *

Affected
Qualcomm, Inc.
Snapdragon

AR8035

Affected
Qualcomm, Inc.
Snapdragon

CSRA6620

Affected
Qualcomm, Inc.
Snapdragon

CSRA6640

Affected
Qualcomm, Inc.
Snapdragon

FastConnect 6200

Affected
Qualcomm, Inc.
Snapdragon

FastConnect 6700

Affected
Qualcomm, Inc.
Snapdragon

FastConnect 6800

Affected
Qualcomm, Inc.
Snapdragon

FastConnect 6900

Affected
Qualcomm, Inc.
Snapdragon

FastConnect 7800

Affected
Qualcomm, Inc.
Snapdragon

Flight RB5 5G Platform

Affected
Qualcomm, Inc.
Snapdragon

QAM8255P

Affected
Qualcomm, Inc.
Snapdragon

QAM8295P

Affected
Qualcomm, Inc.
Snapdragon

QAM8650P

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.