7.8

CVE-2023-33110

The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.

Data is provided by the National Vulnerability Database (NVD)
QualcommSsg2115p Firmware Version-
   QualcommSsg2115p Version-
QualcommSsg2125p Firmware Version-
   QualcommSsg2125p Version-
QualcommSw5100 Firmware Version-
   QualcommSw5100 Version-
QualcommSw5100p Firmware Version-
   QualcommSw5100p Version-
QualcommSxr1120 Firmware Version-
   QualcommSxr1120 Version-
QualcommSxr1230p Firmware Version-
   QualcommSxr1230p Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
QualcommSxr2230p Firmware Version-
   QualcommSxr2230p Version-
QualcommWcd9306 Firmware Version-
   QualcommWcd9306 Version-
QualcommWcd9326 Firmware Version-
   QualcommWcd9326 Version-
QualcommWcd9330 Firmware Version-
   QualcommWcd9330 Version-
QualcommWcd9335 Firmware Version-
   QualcommWcd9335 Version-
QualcommWcd9340 Firmware Version-
   QualcommWcd9340 Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
QualcommWcd9360 Firmware Version-
   QualcommWcd9360 Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9371 Firmware Version-
   QualcommWcd9371 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcn3610 Firmware Version-
   QualcommWcn3610 Version-
QualcommWcn3615 Firmware Version-
   QualcommWcn3615 Version-
QualcommWcn3620 Firmware Version-
   QualcommWcn3620 Version-
QualcommWcn3660 Firmware Version-
   QualcommWcn3660 Version-
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b Version-
QualcommWcn3680 Firmware Version-
   QualcommWcn3680 Version-
QualcommWcn3680b Firmware Version-
   QualcommWcn3680b Version-
QualcommWcn3910 Firmware Version-
   QualcommWcn3910 Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3988 Firmware Version-
   QualcommWcn3988 Version-
QualcommWcn3990 Firmware Version-
   QualcommWcn3990 Version-
QualcommWcn3999 Firmware Version-
   QualcommWcn3999 Version-
QualcommWcn6740 Firmware Version-
   QualcommWcn6740 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8832 Firmware Version-
   QualcommWsa8832 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.255
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

CWE-823 Use of Out-of-range Pointer Offset

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.