CVE-2024-23377: Use of Out-of-range Pointer Offset in ComputerVision
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23377?
CVE-2024-23377 has a high severity level due to the potential for memory corruption in the affected Qualcomm devices.
How do I fix CVE-2024-23377?
To fix CVE-2024-23377, it is recommended to apply the latest firmware updates provided by Qualcomm for the affected devices.
What types of devices are affected by CVE-2024-23377?
CVE-2024-23377 affects various Qualcomm devices including WSA and Snapdragon platforms, specifically firmware versions of WSA8845, WSA8840, and others.
What are the potential impacts of CVE-2024-23377?
The impact of CVE-2024-23377 includes potential system instability or crashes due to memory corruption when the IOCTL command is improperly manipulated.
Is CVE-2024-23377 exploitable over a network?
CVE-2024-23377 is not classified as a network exploitable vulnerability since it requires user-space interaction to trigger the memory corruption.