CVE-2021-30351
9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.02% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-01-03 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| qualcomm | apq8009 |
| qualcomm | apq8009 firmware |
| qualcomm | apq8009w |
| qualcomm | apq8009w firmware |
| qualcomm | apq8017 |
| qualcomm | apq8017 firmware |
| qualcomm | aqt1000 |
| qualcomm | aqt1000 firmware |
| qualcomm | ar8031 |
| qualcomm | ar8031 firmware |
| qualcomm | ar8035 |
| qualcomm | ar8035 firmware |
| qualcomm | ar9380 |
| qualcomm | ar9380 firmware |
| qualcomm | csr8811 |
| qualcomm | csr8811 firmware |
| qualcomm | csra6620 |
| qualcomm | csra6620 firmware |
| qualcomm | csra6640 |
| qualcomm | csra6640 firmware |
| qualcomm | csrb31024 |
| qualcomm | csrb31024 firmware |
| qualcomm | fsm10055 |
| qualcomm | fsm10055 firmware |
| qualcomm | fsm10056 |
| qualcomm | fsm10056 firmware |
| qualcomm | ipq4018 |
| qualcomm | ipq4018 firmware |
| qualcomm | ipq4028 |
| qualcomm | ipq4028 firmware |
| qualcomm | ipq4029 |
| qualcomm | ipq4029 firmware |
| qualcomm | ipq6000 |
| qualcomm | ipq6000 firmware |
| qualcomm | ipq6010 |
| qualcomm | ipq6010 firmware |
| qualcomm | ipq6018 |
| qualcomm | ipq6018 firmware |
| qualcomm | ipq6028 |
| qualcomm | ipq6028 firmware |
References
→ the Explorer · watch your stack · NVD