CVE-2023-33110
Last modified
CVE-2023-33110 is a high-severity vulnerability rated 7/10 on the CVSS scale. The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.. EPSS estimates a 0.08% chance of exploitation in the next 30 days.
Description
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Snapdragon 425 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 427 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 429 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 430 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 435 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 439 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 450 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 460 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480\+ 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 625 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 626 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 630 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 632 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 636 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 660 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 662 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 665 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 670 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 675 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 678 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 680 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 685 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 690 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 695 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 710 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 712 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 720g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 730 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 730g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 732g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 750g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 765 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 765g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 768g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 778g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 778g\+ 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 780g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 782g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 7c Compute Platform Firmware | All versions |
| Qualcomm | Snapdragon 7c Gen 2 Compute Platform Firmware | All versions |
| Qualcomm | Snapdragon 7c\+ Gen 3 Compute Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 820 Automotive Platform Firmware | All versions |
| Qualcomm | Snapdragon 820 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 821 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 835 Mobile Pc Platform Firmware | All versions |
| Qualcomm | Snapdragon 845 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 850 Mobile Compute Platform Firmware | All versions |
Showing 50 of 123 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-33110?
How severe is CVE-2023-33110?
How do I fix CVE-2023-33110?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-33105Transient DOS in WLAN Host and Firmware when large number of…7.5
- CVE-2023-33106Memory corruption while submitting a large list of sync poin…7.8
- CVE-2023-33107Memory corruption in Graphics Linux while assigning shared v…7.8
- CVE-2023-33108Memory corruption in Graphics Driver when destroying a conte…7.8
- CVE-2023-33109Transient DOS while processing a WMI P2P listen start comman…7.5
- CVE-2023-3311A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2023-33111Information disclosure when VI calibration state set by ADSP…5.5
- CVE-2023-33112Transient DOS when WLAN firmware receives "reassoc response"…7.5
- CVE-2023-33113Memory corruption when resource manager sends the host kerne…7.8
- CVE-2023-33114Memory corruption while running NPU, when NETWORK_UNLOAD and…7.8
- CVE-2023-33115Memory corruption while processing buffer initialization, wh…7.8
- CVE-2023-33116Transient DOS while parsing ieee80211_parse_mscs_ie in WIN W…7.5
Are you affected by CVE-2023-33110?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
