Reachable Assertion in Qualcomm products - CVE-2021-35101
Published: June 7, 2022
Vulnerability identifier: #VU64039
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35101
CWE-ID: CWE-617
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of writes to virtual GICR control in Kernel. A local attacker can cause assertion failure in the hypervisor and perform a denial of service attack.
Affected software
SD 8cx Gen2
WSA8815
WSA8810
WCN3998
WCD9380
WCD9341
WCD9340
SDXR2 5G
SDX55M
SD888 5G
SD870
SD865 5G
AQT1000
SD 8CX
QCA6436
QCA6431
QCA6430
QCA6426
QCA6421
QCA6420
QCA6391
QCA6390
SA9000P
SA8540P
WSA8815
WSA8810
WCN3998
WCD9380
WCD9341
WCD9340
SDXR2 5G
SDX55M
SD888 5G
SD870
SD865 5G
AQT1000
SD 8CX
QCA6436
QCA6431
QCA6430
QCA6426
QCA6421
QCA6420
QCA6391
QCA6390
SA9000P
SA8540P
How to mitigate CVE-2021-35101
Install updates from vendor's website.