First published: Fri Apr 01 2022(Updated: )
Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm APQ8096AU Firmware | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm AR6003 Firmware | ||
Qualcomm AR6003 Firmware | ||
Qualcomm MDM8215M | ||
Qualcomm MDM8215M | ||
Qualcomm MDM8215M | ||
Qualcomm MDM8215M Firmware | ||
Qualcomm MDM8615M | ||
Qualcomm MDM8615M Firmware | ||
Qualcomm MDM9215 | ||
Qualcomm MDM9215 | ||
Qualcomm MDM9310 | ||
Qualcomm MDM9310 | ||
Qualcomm MDM9615M Firmware | ||
Qualcomm MDM9615 firmware | ||
Qualcomm MDM9615M Firmware | ||
Qualcomm MDM9615M Firmware | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCA6564A | ||
Qualcomm QCA6564A Firmware | ||
Qualcomm QCA6564AU Firmware | ||
Qualcomm QCA6564A | ||
Qualcomm QCA6574A Firmware | ||
qualcomm qca6574a firmware | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm QCA6584AU Firmware | ||
Qualcomm QCA6584AU firmware | ||
Qualcomm QCA6696 Firmware | ||
Qualcomm QCA6696 Firmware | ||
Qualcomm SA6145P Firmware | ||
Qualcomm SA6145P Firmware | ||
Qualcomm SA6150P Firmware | ||
Qualcomm SA6150P Firmware | ||
Qualcomm SA6155 | ||
Qualcomm SA6155P | ||
Qualcomm SA8145P | ||
Qualcomm SA8145P Firmware | ||
Qualcomm SA8150P Firmware | ||
Qualcomm SA8150P Firmware | ||
Qualcomm SA8155 | ||
Qualcomm SA8155P Firmware | ||
Qualcomm SA8195P | ||
Qualcomm SA8195P Firmware | ||
Qualcomm SA8540P | ||
Qualcomm SA8540P Firmware | ||
Qualcomm SA9000P Firmware | ||
Qualcomm SA9000P Firmware | ||
Qualcomm SDX55M Firmware | ||
Qualcomm SDX55 Firmware | ||
Qualcomm SDX55M Firmware | ||
Qualcomm SDX55M Firmware | ||
Qualcomm WCD9341 | ||
Qualcomm WCD9341 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35115 is a vulnerability in Qualcomm Snapdragon Auto and Snapdragon Mobile that results from improper handling of multiple sessions supported by the PVM backend, leading to a use-after-free vulnerability.
CVE-2021-35115 has a severity rating of 7.8 (high).
CVE-2021-35115 affects Qualcomm Snapdragon Auto and Snapdragon Mobile.
CVE-2021-35115 can be exploited by attackers who are able to send specially crafted packets to the vulnerable system, leading to a use-after-free condition.
Yes, a fix for CVE-2021-35115 is provided by Qualcomm. It is recommended to apply the necessary patches to mitigate the vulnerability.