CVE-2021-30294

HIGH

Snapdragon Auto-Snapdragon Industrial IOT - Memory Corruption

Title source: llm
STIX 2.1

Description

Potential null pointer dereference in KGSL GPU auxiliary command due to improper validation of user input in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0003
EPSS Percentile 9.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-476
Status published
Products (41)
qualcomm/qca6174a_firmware
qualcomm/qca6574_firmware
qualcomm/qca6574a_firmware
qualcomm/qca6574au_firmware
qualcomm/qca6595au_firmware
qualcomm/qca6696_firmware
qualcomm/qca9377_firmware
qualcomm/qcm6490_firmware
qualcomm/qcs6490_firmware
qualcomm/sa6145p_firmware
... and 31 more
Published Sep 09, 2021
Tracked Since Feb 18, 2026