VulnerabilityModified
CVE-2021-35120
Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
MEDIUM 6.7EPSS 0.15%
Does this matter?
Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.
Description
Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.15% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- qualcomm/apq8053 firmware · qualcomm/aqt1000 firmware · qualcomm/ar8031 firmware · qualcomm/ar8035 firmware · qualcomm/csra6620 firmware · qualcomm/csra6640 firmware · qualcomm/mdm9150 firmware · qualcomm/msm8953 firmware · qualcomm/qca6390 firmware · qualcomm/qca6391 firmware · qualcomm/qca6420 firmware · qualcomm/qca6426 firmware · qualcomm/qca6430 firmware · qualcomm/qca6436 firmware · qualcomm/qca6574 firmware · qualcomm/qca6574a firmware · qualcomm/qca6574au firmware · qualcomm/qca6595au firmware · qualcomm/qca8337 firmware · qualcomm/qcm2290 firmware · +40 more
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/june-2022-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/june-2022-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.