CVE-2023-33110: Use of Out-of-range Pointer Offset in Audio
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33110?
CVE-2023-33110 has a moderate severity due to the possibility of memory corruption caused by a race condition.
How do I fix CVE-2023-33110?
To mitigate CVE-2023-33110, apply the recommended updates provided by Qualcomm for the affected Snapdragon mobile platforms.
What platforms are affected by CVE-2023-33110?
CVE-2023-33110 impacts various Qualcomm Snapdragon mobile platforms and their associated firmware.
What type of vulnerability is CVE-2023-33110?
CVE-2023-33110 is categorized as a race condition vulnerability affecting the PCM host voice audio driver.
Is there any public reference for CVE-2023-33110?
Yes, Qualcomm has issued a security bulletin detailing CVE-2023-33110 and its implications.