#VU64039 Reachable Assertion in Qualcomm products - CVE-2021-35101
Published: June 7, 2022
Vulnerability identifier: #VU64039
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-35101
CWE-ID: CWE-617
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
AQT1000
QCA6390
QCA6391
QCA6420
QCA6421
QCA6426
QCA6430
QCA6431
QCA6436
SD 8CX
SD 8cx Gen2
SD865 5G
SD870
SD888 5G
SDX55M
SDXR2 5G
WCD9340
WCD9341
WCD9380
WCN3998
WSA8810
WSA8815
SA8540P
SA9000P
AQT1000
QCA6390
QCA6391
QCA6420
QCA6421
QCA6426
QCA6430
QCA6431
QCA6436
SD 8CX
SD 8cx Gen2
SD865 5G
SD870
SD888 5G
SDX55M
SDXR2 5G
WCD9340
WCD9341
WCD9380
WCN3998
WSA8810
WSA8815
SA8540P
SA9000P
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of writes to virtual GICR control in Kernel. A local attacker can cause assertion failure in the hypervisor and perform a denial of service attack.
Remediation
Install updates from vendor's website.