Use-after-free in Qualcomm products - CVE-2021-1947
Published: August 3, 2021
Vulnerability identifier: #VU55507
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1947
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in kernel graphics driver. A local user can run a specially crafted program to trigger a use-after-free error and execute arbitrary code elevated privileges.
Affected software
SDA429W
WCD9341
WCD9340
WCD9335
WCD9326
SM7250
SM4125
SDX55M
SDM830
WCD9370
SD870
SD8655G
SD768G
SD765G
SD765
SD750G
SD6905G
SD662
WCN3980
WSA8835
WSA8830
WSA8815
WSA8810
WCN6851
WCN6850
WCN3998
WCN3991
WCN3990
WCN3988
SD660
WCN3950
WCN3910
WCN3680B
WCN3660B
WCN3620
WCN3615
WCN3610
WCD9385
WCD9380
WCD9375
QCA6391
QCA9887
QCA9886
QCA9882
QCA9880
QCA9563
QCA9561
QCA8337
QCA6426
QCA9888
QCA6390
QCA6320
IPQ8069
IPQ8068
IPQ8065
AR9380
QCM2290
SD460
SD429
QSW8573
QRB5165
QET4101
QCS6125
QCS4290
QCS2290
QCM6125
QCM4290
APQ8009W
QCA9994
QCA9992
QCA9990
QCA9984
QCA9982
QCA9898
QCA9896
QCA9889
SDX55
SDM429W
SD855
SD665
QCA9558
QCA9531
MSM8953
MSM8909W
IPQ8064
APQ8053
QCA9980
WCD9341
WCD9340
WCD9335
WCD9326
SM7250
SM4125
SDX55M
SDM830
WCD9370
SD870
SD8655G
SD768G
SD765G
SD765
SD750G
SD6905G
SD662
WCN3980
WSA8835
WSA8830
WSA8815
WSA8810
WCN6851
WCN6850
WCN3998
WCN3991
WCN3990
WCN3988
SD660
WCN3950
WCN3910
WCN3680B
WCN3660B
WCN3620
WCN3615
WCN3610
WCD9385
WCD9380
WCD9375
QCA6391
QCA9887
QCA9886
QCA9882
QCA9880
QCA9563
QCA9561
QCA8337
QCA6426
QCA9888
QCA6390
QCA6320
IPQ8069
IPQ8068
IPQ8065
AR9380
QCM2290
SD460
SD429
QSW8573
QRB5165
QET4101
QCS6125
QCS4290
QCS2290
QCM6125
QCM4290
APQ8009W
QCA9994
QCA9992
QCA9990
QCA9984
QCA9982
QCA9898
QCA9896
QCA9889
SDX55
SDM429W
SD855
SD665
QCA9558
QCA9531
MSM8953
MSM8909W
IPQ8064
APQ8053
QCA9980
How to mitigate CVE-2021-1947
Install updates from vendor's website.
External References
- https://www.qualcomm.com/company/product-security/bulletins/august-2021-bulletin
- https://source.codeaurora.org/quic/le/kernel/msm-4.19/commit/?id=cb82ed90520b6801e6b0ec6bac6821cd347e3de7
- https://source.codeaurora.org/quic/le/kernel/msm-4.19/commit/?id=70c13b73f1ea7a30a730ced48a59d366898677bc
- https://source.codeaurora.org/quic/le/kernel/msm-4.19/commit/?id=a637a43b7995cf905f1d0d059b418ee57e60aa67
- https://source.codeaurora.org/quic/le/kernel/msm-4.19/commit/?id=851a03f61d90566e37408240b2f71ed34f8cc73a