Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability (CVE-2021-1906)
Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.
A local attacker, without authentication, can achieve partial data exposure, complete denial of service or system unavailability. Federal agencies are required to remediate by 2021-11-17 under CISA BOD 22-01.
This vulnerability affects Qualcomm Multiple Chipsets. Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Exploitation requires local access, low attack complexity, no authentication required, and no user interaction required.
Probably yes if any of these apply:
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2021-11-17.
Manual remediation steps
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.