← Vulnerability feed

Vulnerability record · CVE-2023-33110 · published 2 January 2024

CVE-2023-33110: Qualcomm snapdragon 425 mobile platform firmware race condition vulnerability

Qualcomm · Snapdragon 425 Mobile Platform Firmware

The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.

7.0 CVSS 3.1 High EPSS 0.08% · top 99.9% CWE-823 · CWE-823CWE-362 · Race condition
7.0CVSS 3.1 base score
0.08%EPSS exploitation probability, 30 days
NoNot in CISA KEV
123Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

123 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-33110 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-21385Qualcomm chipset firmware memory corruption via alignment integer overflowA memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It af…KEVEPSS 1.3%analysed7.8CVE-2023-33107Qualcomm Graphics Linux integer overflow memory corruptionCVE-2023-33107 is an integer overflow (CWE-190) in Qualcomm Graphics Linux that causes memory corruption when a shared virtual memory region is assig…KEVEPSS 0.89%analysed9.8CVE-2025-27071Qualcomm fastconnect 6800 firmware classic buffer overflow vulnerabilityMemory corruption while processing specific files in Powerline Communication Firmware.EPSS 0.18%9.8CVE-2023-22388Qualcomm 315 5g iot modem firmware out-of-bounds write vulnerabilityMemory Corruption in Multi-mode Call Processor while processing bit mask API.EPSS 0.35%9.8CVE-2023-22385Qualcomm 315 5g iot modem firmware out-of-bounds write vulnerabilityMemory Corruption in Data Modem while making a MO call or MT VOLTE call.EPSS 0.35%8.4CVE-2024-23365Qualcomm qamsrv1m firmware use after free vulnerabilityMemory corruption while releasing shared resources in MinkSocket listener thread.EPSS 0.13%8.2CVE-2025-21484Qualcomm sm8750 firmware vulnerabilityInformation disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.EPSS 0.26%8.2CVE-2025-21488Qualcomm fastconnect 6200 firmware vulnerabilityInformation disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2023-33110), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.