Race condition in Qualcomm products - CVE-2021-35095
Published: April 5, 2022
Vulnerability identifier: #VU61882
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35095
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a race condition when handling queue client registrations in Linux kernel. A local application can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
AR8035
QCA8081
QCA8337
SD8Gen15G
SDX65
WCD9380
WCN6855
WCN6856
WSA8830
WSA8835
Google Android
QCA8081
QCA8337
SD8Gen15G
SDX65
WCD9380
WCN6855
WCN6856
WSA8830
WSA8835
Google Android
How to mitigate CVE-2021-35095
Install updates from vendor's website.
Google Android - addressed in versions 10 2022-04-05, 11 2022-04-05, 12L 2022-04-05, 12 2022-04-05