MEDIUM

CVE-2021-1906

Qualcomm Apq8009 Firmware 2021-05-07 CVSS v3.1
CVSS
5.5
KEV

Description

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Summary dbcve.org

This is a GPU memory management vulnerability in Qualcomm Snapdragon chipsets where improper handling of address deregistration on failure conditions prevents subsequent GPU address allocations from succeeding. When a failure occurs during address deregistration, the GPU cannot allocate new addresses, causing potential denial of service for graphics operations.

Mitigation

Apply vendor-provided firmware/driver updates from Qualcomm that address the GPU address registration handling logic. This is a chipset-level fix requiring OEM/device manufacturer distribution.

Patch Commit

EPSS Score

0.52%
Probability of exploitation in next 30 days
41.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE