First published: Mon May 02 2022(Updated: )
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm aqt1000 firmware | ||
Qualcomm aqt1000 | ||
Qualcomm qca6390 firmware | ||
Qualcomm qca6390 | ||
qualcomm qca6391 firmware | ||
qualcomm qca6391 | ||
Qualcomm qca6420 firmware | ||
Qualcomm qca6420 | ||
qualcomm qca6421 firmware | ||
qualcomm qca6421 | ||
qualcomm qca6426 firmware | ||
qualcomm qca6426 | ||
Qualcomm qca6430 firmware | ||
Qualcomm qca6430 | ||
qualcomm qca6431 firmware | ||
qualcomm qca6431 | ||
qualcomm qca6436 firmware | ||
qualcomm qca6436 | ||
Qualcomm qcm6490 firmware | ||
Qualcomm qcm6490 | ||
Qualcomm qcs6490 firmware | ||
Qualcomm qcs6490 | ||
qualcomm qrb5165 firmware | ||
qualcomm qrb5165 | ||
qualcomm qrb5165m firmware | ||
qualcomm qrb5165m | ||
qualcomm qrb5165n firmware | ||
qualcomm qrb5165n | ||
qualcomm qsm8350 firmware | ||
qualcomm qsm8350 | ||
Qualcomm sa8540p firmware | ||
Qualcomm sa8540p | ||
qualcomm sa9000p firmware | ||
qualcomm sa9000p | ||
qualcomm SD 8CX firmware | ||
qualcomm SD 8CX | ||
qualcomm sd 8cx gen2 firmware | ||
qualcomm sd 8cx gen2 | ||
qualcomm sd690 5g firmware | ||
qualcomm sd690 5g | ||
Qualcomm sd750g firmware | ||
Qualcomm sd750g | ||
Qualcomm sd765 firmware | ||
Qualcomm sd765 | ||
Qualcomm sd765g firmware | ||
Qualcomm sd765g | ||
Qualcomm sd768g firmware | ||
Qualcomm sd768g | ||
qualcomm sd778g firmware | ||
qualcomm sd778g | ||
qualcomm sd780g firmware | ||
qualcomm sd780g | ||
qualcomm sd865 5g firmware | ||
qualcomm sd865 5g | ||
Qualcomm sd870 firmware | ||
Qualcomm sd870 | ||
Qualcomm sd888 firmware | ||
Qualcomm sd888 | ||
qualcomm sd888 5g firmware | ||
qualcomm sd888 5g | ||
Qualcomm sdx55m firmware | ||
Qualcomm sdx55m | ||
qualcomm sdxr2 5g firmware | ||
qualcomm sdxr2 5g | ||
qualcomm sm7250p firmware | ||
qualcomm sm7250p | ||
qualcomm sm7315 firmware | ||
qualcomm sm7315 | ||
qualcomm sm7325p firmware | ||
qualcomm sm7325p | ||
qualcomm wcd9340 firmware | ||
qualcomm wcd9340 | ||
qualcomm wcd9341 firmware | ||
qualcomm wcd9341 | ||
Qualcomm wcd9370 firmware | ||
Qualcomm wcd9370 | ||
Qualcomm wcd9375 firmware | ||
Qualcomm wcd9375 | ||
qualcomm wcd9380 firmware | ||
qualcomm wcd9380 | ||
qualcomm wcd9385 firmware | ||
qualcomm wcd9385 | ||
qualcomm wcn3988 firmware | ||
Qualcomm WCN3988 | ||
Qualcomm WCN3991 Firmware | ||
Qualcomm WCN3991 Firmware | ||
Qualcomm wcn3998 firmware | ||
Qualcomm wcn3998 | ||
Qualcomm wcn6740 firmware | ||
qualcomm wcn6740 | ||
qualcomm wcn6750 firmware | ||
qualcomm wcn6750 | ||
Qualcomm WCN6850 Firmware | ||
Qualcomm WCN6850 Firmware | ||
Qualcomm WCN6851 Firmware | ||
Qualcomm WCN6851 Firmware | ||
Qualcomm wcn6855 firmware | ||
qualcomm wcn6855 | ||
Qualcomm wcn6856 firmware | ||
qualcomm wcn6856 | ||
qualcomm wcn7850 firmware | ||
Qualcomm WCN7850 | ||
qualcomm wcn7851 firmware | ||
qualcomm wcn7851 | ||
qualcomm wsa8810 firmware | ||
qualcomm wsa8810 | ||
qualcomm wsa8815 firmware | ||
qualcomm wsa8815 | ||
qualcomm wsa8830 firmware | ||
qualcomm wsa8830 | ||
qualcomm wsa8835 firmware | ||
qualcomm wsa8835 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2021-35090 vulnerability has a severity rating that indicates a significant risk of hypervisor memory corruption due to a race condition.
To mitigate CVE-2021-35090, apply the latest security updates provided by your device manufacturer or rely on the updates from Qualcomm for affected products.
CVE-2021-35090 affects various Qualcomm Snapdragon products including those in automotive, compute, connectivity, industrial IOT, and mobile sectors.
CVE-2021-35090 could allow an attacker to exploit hypervisor-level vulnerabilities, potentially leading to unauthorized access or disruption of system operations.
As of the latest reports, there have been no confirmed instances of active exploitation of CVE-2021-35090 in the wild.