CVE-2024-23370: Use After Free in Automotive Multimedia
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23370?
The severity of CVE-2024-23370 is currently classified as high due to the potential for memory corruption.
How do I fix CVE-2024-23370?
To address CVE-2024-23370, it is recommended to apply the latest firmware updates provided by Qualcomm for affected devices.
What systems are affected by CVE-2024-23370?
CVE-2024-23370 affects multiple Qualcomm firmware versions across various products, including WSA8835, WSA8830, and WCN3988.
What kind of attack does CVE-2024-23370 enable?
CVE-2024-23370 enables potential attackers to execute arbitrary code due to memory corruption vulnerabilities when handling IOCTL calls.
Is CVE-2024-23370 being actively exploited in the wild?
As of the latest information, there is no confirmed evidence that CVE-2024-23370 is being actively exploited in the wild.