Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
Review the upstream advisory, identify the affected product in your inventory, and apply the vendor update when one is available.
Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability is listed in the HOL Guard supply-chain feed, but affected software is not mapped to a package. Review the upstream advisory for the affected product and vendor guidance. This vulnerability is known to be exploited in the wild. Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
Affected software not mapped. Review the upstream record for vendor-specific product and version guidance.
No references were reported by the source.
Reported by CISA KEV (kev).
HOL Guard can help your team monitor supply-chain activity while the upstream record is clarified.
Explore HOL GuardMultiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
Review the upstream advisory, identify the affected product in your inventory, and apply the vendor update when one is available.
Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability is listed in the HOL Guard supply-chain feed, but affected software is not mapped to a package. Review the upstream advisory for the affected product and vendor guidance. This vulnerability is known to be exploited in the wild. Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
Affected software not mapped. Review the upstream record for vendor-specific product and version guidance.
No references were reported by the source.
Reported by CISA KEV (kev).
HOL Guard can help your team monitor supply-chain activity while the upstream record is clarified.
Explore HOL Guard