Race condition in Qualcomm products - CVE-2021-35095

 

Race condition in Qualcomm products - CVE-2021-35095

Published: April 5, 2022


Vulnerability identifier: #VU61882
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35095
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a race condition when handling queue client registrations in Linux kernel. A local application can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

AR8035
QCA8081
QCA8337
SD8Gen15G
SDX65
WCD9380
WCN6855
WCN6856
WSA8830
WSA8835
Google Android

How to mitigate CVE-2021-35095

Install updates from vendor's website.

Google Android - addressed in versions 10 2022-04-05, 11 2022-04-05, 12L 2022-04-05, 12 2022-04-05

External References

Related Security Bulletins