CVE-2023-33106: Use of Out-of-range Pointer Offset in Graphics
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTLKGSLGPUAUXCOMMAND.
Other sources
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTLKGSLGPUAUXCOMMAND.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Adobe After Effects 2025from your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Adobe Dimensionfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Adobe Experience Managerfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Adobe Illustrator 2024from your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Adobe InDesign 2025from your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Adobe Preludefrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Adobe Substance 3D Samplerfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Adobe Substance 3D Stagerfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Androidfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Apache Strutsfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Atlassian Bitbucketfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Atlassian Confluence Server and Data Serverfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Atlassian Confluence Server/Data Centerfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Atlassian Jirafrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Azure Logic Appsfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Bamboofrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
FortiGuard FortiPAMfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
FortiOSfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Microsoft Power Platformfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Microsoft Windows Operating Systemfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Qualcomm Multiple Chipsetsfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
SAP Business Technology Platformfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
Trimble ProDesign 3Dfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
VMware Workspace ONE Launcherfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
- Remove
Remove
WebKitfrom your environment.Discontinue use of the product if remediation or mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-33106?
CVE-2023-33106 is a vulnerability that involves the use of out-of-range pointer offset in Graphics on multiple Qualcomm chipsets.
What is the severity of CVE-2023-33106?
The severity of CVE-2023-33106 is high, with a CVSS score of 8.4.
Which software is affected by CVE-2023-33106?
CVE-2023-33106 affects Google Android and multiple Qualcomm chipsets.
How can I fix CVE-2023-33106?
To fix CVE-2023-33106, it is recommended to apply the necessary patches provided by Google and Qualcomm.
Where can I find more information about CVE-2023-33106?
You can find more information about CVE-2023-33106 in the references provided: [Link 1](https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/1e46e81dbeb69aafd5842ce779f07e617680fd58), [Link 2](https://source.android.com/docs/security/bulletin/2023-12-01), [Link 3](https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin).