CVE-2021-1933: Out-of-bounds Read
UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1933?
CVE-2021-1933 has been classified with a high severity due to the potential for remote code execution.
How do I fix CVE-2021-1933?
To mitigate CVE-2021-1933, update your device firmware to the latest version provided by Qualcomm or your device manufacturer.
What devices are affected by CVE-2021-1933?
CVE-2021-1933 affects a variety of Qualcomm Snapdragon devices, including Android smartphones and IoT devices.
Can CVE-2021-1933 be exploited remotely?
Yes, CVE-2021-1933 can be exploited remotely if an attacker sends a malicious invite message.
What should I do if I cannot update my device for CVE-2021-1933?
If updating is not possible for CVE-2021-1933, consider disabling features that rely on the vulnerable components until a patch is available.