#VU63087 Time-of-check Time-of-use (TOCTOU) Race Condition in Qualcomm products - CVE-2021-35082
Published: May 12, 2022 / Updated: May 12, 2022
MDM9206
QCA9377
QCA9367
Qualcomm
Description
The vulnerability allows a remote attacker to compromise the affected device.
The vulnerability exists due to race condition between PDCP and RRC tasks within NB1 component. A remote attacker can send specially crafted traffic after a valid RRC security mode command packet has been received and execute arbitrary code on the system.