First published: Mon Oct 07 2024(Updated: )
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
qualcomm wsa8835 firmware | ||
qualcomm wsa8835 | ||
All of | ||
qualcomm wsa8830 firmware | ||
qualcomm wsa8830 | ||
All of | ||
qualcomm wcn3988 firmware | ||
Qualcomm WCN3988 | ||
All of | ||
qualcomm wcn3980 firmware | ||
Qualcomm Wcn3980 | ||
All of | ||
qualcomm sw5100p firmware | ||
qualcomm sw5100p | ||
All of | ||
qualcomm sw5100 firmware | ||
qualcomm sw5100 | ||
All of | ||
Qualcomm Snapdragon Auto 5G-RF Gen 2 Firmware | ||
qualcomm snapdragon auto 5g modem-rf gen 2 | ||
All of | ||
Qualcomm qca9377 firmware | ||
Qualcomm qca9377 | ||
All of | ||
Qualcomm qca9367 firmware | ||
Qualcomm qca9367 | ||
All of | ||
qualcomm qca6698aq firmware | ||
qualcomm qca6698aq | ||
All of | ||
qualcomm QCA6584AU firmware | ||
qualcomm QCA6584AU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23370 is currently classified as high due to the potential for memory corruption.
To address CVE-2024-23370, it is recommended to apply the latest firmware updates provided by Qualcomm for affected devices.
CVE-2024-23370 affects multiple Qualcomm firmware versions across various products, including WSA8835, WSA8830, and WCN3988.
CVE-2024-23370 enables potential attackers to execute arbitrary code due to memory corruption vulnerabilities when handling IOCTL calls.
As of the latest information, there is no confirmed evidence that CVE-2024-23370 is being actively exploited in the wild.