CVE-2021-1940

Use after free can occur due to improper handling of response from firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:aqt1000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:ar8031_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ar8031:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ar8035:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:csra6620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:csra6620:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:csra6640_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:csra6640:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:fsm10055_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fsm10055:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:fsm10056_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fsm10056:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6391:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6420:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6430:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:qca6564_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6564:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:qualcomm:qca6564a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6564a:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:qualcomm:qca6564au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6564au:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574a:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:qualcomm:qca6584au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6584au:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6595au:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6696:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:qualcomm:qca8337_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca8337:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:qualcomm:qcm6125_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcm6125:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:qualcomm:qcs405_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs405:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:qualcomm:qcs410_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs410:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:qualcomm:qcs610_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs610:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:qualcomm:qcs6125_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs6125:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:qualcomm:sa415m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa415m:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:qualcomm:sa515m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa515m:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6145p:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155p:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155p:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8195p:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:qualcomm:sd_675_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_675:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:qualcomm:sd_8c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_8c:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:qualcomm:sd_8cx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_8cx:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:qualcomm:sd660_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd660:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:qualcomm:sd665_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd665:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:qualcomm:sd675_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd675:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:qualcomm:sd678_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd678:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:qualcomm:sd720g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd720g:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:qualcomm:sd730_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd730:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:qualcomm:sd855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd855:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:qualcomm:sda429w_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sda429w:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:qualcomm:sdx50m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdx50m:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdx55:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:qualcomm:sdx55m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdx55m:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:qualcomm:sm6250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm6250:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:qualcomm:sm6250p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm6250p:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:qualcomm:wcd9335_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9335:-:*:*:*:*:*:*:*

Configuration 51 (hide)

AND
cpe:2.3:o:qualcomm:wcd9340_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9340:-:*:*:*:*:*:*:*

Configuration 52 (hide)

AND
cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9341:-:*:*:*:*:*:*:*

Configuration 53 (hide)

AND
cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9370:-:*:*:*:*:*:*:*

Configuration 54 (hide)

AND
cpe:2.3:o:qualcomm:wcd9375_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9375:-:*:*:*:*:*:*:*

Configuration 55 (hide)

AND
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*

Configuration 56 (hide)

AND
cpe:2.3:o:qualcomm:wcn3610_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3610:-:*:*:*:*:*:*:*

Configuration 57 (hide)

AND
cpe:2.3:o:qualcomm:wcn3620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3620:-:*:*:*:*:*:*:*

Configuration 58 (hide)

AND
cpe:2.3:o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3660b:-:*:*:*:*:*:*:*

Configuration 59 (hide)

AND
cpe:2.3:o:qualcomm:wcn3950_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3950:-:*:*:*:*:*:*:*

Configuration 60 (hide)

AND
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*

Configuration 61 (hide)

AND
cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3988:-:*:*:*:*:*:*:*

Configuration 62 (hide)

AND
cpe:2.3:o:qualcomm:wcn3990_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3990:-:*:*:*:*:*:*:*

Configuration 63 (hide)

AND
cpe:2.3:o:qualcomm:wcn3991_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3991:-:*:*:*:*:*:*:*

Configuration 64 (hide)

AND
cpe:2.3:o:qualcomm:wcn3998_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3998:-:*:*:*:*:*:*:*

Configuration 65 (hide)

AND
cpe:2.3:o:qualcomm:wcn3999_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3999:-:*:*:*:*:*:*:*

Configuration 66 (hide)

AND
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*

Configuration 67 (hide)

AND
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:45

Type Values Removed Values Added
CVSS v2 : 7.2
v3 : 7.8
v2 : 7.2
v3 : 8.4
References () http://packetstormsecurity.com/files/172856/Qualcomm-NPU-Use-After-Free-Information-Leak.html - () http://packetstormsecurity.com/files/172856/Qualcomm-NPU-Use-After-Free-Information-Leak.html -
References () https://www.qualcomm.com/company/product-security/bulletins/july-2021-bulletin - Patch, Vendor Advisory () https://www.qualcomm.com/company/product-security/bulletins/july-2021-bulletin - Patch, Vendor Advisory

12 Jun 2023, 07:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/172856/Qualcomm-NPU-Use-After-Free-Information-Leak.html -

Information

Published : 2021-07-13 06:15

Updated : 2024-11-21 05:45


NVD link : CVE-2021-1940

Mitre link : CVE-2021-1940

CVE.ORG link : CVE-2021-1940


JSON object : View

Products Affected

qualcomm

  • qcm6125_firmware
  • sa6155p
  • wcn3998
  • wcn3660b
  • sa8195p_firmware
  • wcd9380
  • wcd9380_firmware
  • qcs410_firmware
  • sdx55
  • sd665
  • wcn3998_firmware
  • csra6620
  • fsm10055_firmware
  • fsm10056
  • qca6595au_firmware
  • wcd9341_firmware
  • sa515m_firmware
  • wcn3620_firmware
  • sa6145p_firmware
  • qca6391_firmware
  • qca8337_firmware
  • wsa8815_firmware
  • sa6155
  • wcd9370
  • qca6420
  • sm6250p_firmware
  • sd_8cx_firmware
  • wsa8810_firmware
  • qca6574_firmware
  • wcd9340_firmware
  • sd678_firmware
  • ar8031_firmware
  • wcn3999
  • wcn3980
  • wcd9340
  • sd_675
  • wcn3950_firmware
  • wcd9335
  • sa6145p
  • ar8035_firmware
  • aqt1000_firmware
  • qca6430
  • wcd9370_firmware
  • sa8195p
  • qca6595au
  • fsm10055
  • qcs6125_firmware
  • sd720g
  • wcn3980_firmware
  • sda429w_firmware
  • wcn3610
  • wcn3990
  • sd_8cx
  • wcn3991
  • wcn3988
  • csra6640
  • sa515m
  • qca8337
  • qca6584au
  • qca6584au_firmware
  • sm6250p
  • sd730
  • aqt1000
  • qca6391
  • qca6564a_firmware
  • qcs405_firmware
  • sa8155p
  • wcn3950
  • qca6574au
  • qca6696
  • qca6564
  • sd_8c_firmware
  • sd660_firmware
  • qca6574
  • sdx50m
  • wcn3988_firmware
  • qca6420_firmware
  • sdx55m
  • qcm6125
  • sdx50m_firmware
  • wcn3990_firmware
  • sda429w
  • wsa8810
  • wcd9335_firmware
  • sd675
  • qca6430_firmware
  • sd720g_firmware
  • sm6250
  • qca6564au_firmware
  • sd_675_firmware
  • fsm10056_firmware
  • qcs410
  • sd675_firmware
  • sa8155
  • qca6574a
  • sm6250_firmware
  • wcd9341
  • sd730_firmware
  • sd_8c
  • qca6574au_firmware
  • wcd9375
  • wcn3610_firmware
  • sd665_firmware
  • csra6640_firmware
  • csra6620_firmware
  • qca6574a_firmware
  • qcs6125
  • sa8155_firmware
  • wcd9375_firmware
  • wsa8815
  • wcn3991_firmware
  • sa8155p_firmware
  • qcs405
  • sdx55m_firmware
  • qca6564_firmware
  • qcs610
  • sa6155_firmware
  • sdx55_firmware
  • qca6564a
  • qcs610_firmware
  • sa6155p_firmware
  • ar8035
  • ar8031
  • qca6564au
  • sd678
  • qca6696_firmware
  • wcn3660b_firmware
  • sd660
  • sd855
  • sa415m_firmware
  • sd855_firmware
  • wcn3999_firmware
  • sa415m
  • wcn3620
CWE
CWE-416

Use After Free