Use-after-free in Qualcomm products - CVE-2021-30263
Published: November 3, 2021
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to lack of synchronization mechanism when On-Device Logging node open twice concurrently. A local administrator can trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
WSA8815
WSA8810
WCN3999
WCN3998
WCN3980
WCN3950
WCD9370
WCD9341
WCD9340
WCD9335
SDX55M
AQT1000
SD 8C
QCS6125
QCM6125
QCA8337
QCA6430
QCA6420
QCA6391
CSRA6640
CSRA6620
AR8035
AR8031
SDX55
SD855
QCS405