SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-35095

Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile

HIGH 7.0EPSS 0.15%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile

CVSS 3.1
7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.15% probability · 4th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
qualcomm/ar8035 firmware · qualcomm/qca8081 firmware · qualcomm/qca8337 firmware · qualcomm/sd 8 gen1 5g firmware · qualcomm/sdx65 firmware · qualcomm/wcd9380 firmware · qualcomm/wcn6855 firmware · qualcomm/wcn6856 firmware · qualcomm/wsa8830 firmware · qualcomm/wsa8835 firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.