First published: Mon Oct 07 2024(Updated: )
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
qualcomm srv1m firmware | ||
qualcomm srv1m | ||
All of | ||
qualcomm srv1h firmware | ||
qualcomm srv1h | ||
All of | ||
Qualcomm Snapdragon Auto 5G-RF Gen 2 Firmware | ||
qualcomm snapdragon auto 5g modem-rf gen 2 | ||
All of | ||
qualcomm sa9000p firmware | ||
qualcomm sa9000p | ||
All of | ||
qualcomm sa8775p firmware | ||
qualcomm sa8775p | ||
All of | ||
qualcomm sa8770p firmware | ||
qualcomm sa8770p | ||
All of | ||
qualcomm sa8650p firmware | ||
qualcomm sa8650p | ||
All of | ||
qualcomm sa8620p firmware | ||
qualcomm sa8620p | ||
All of | ||
qualcomm sa8255p firmware | ||
qualcomm sa8255p | ||
All of | ||
qualcomm sa7775p firmware | ||
qualcomm sa7775p | ||
All of | ||
qualcomm sa7255p firmware | ||
qualcomm sa7255p | ||
All of | ||
qualcomm qca6698aq firmware | ||
qualcomm qca6698aq | ||
All of | ||
qualcomm QCA6584AU firmware | ||
qualcomm QCA6584AU | ||
All of | ||
qualcomm qamsrv1m firmware | ||
qualcomm qamsrv1m | ||
All of | ||
qualcomm qamsrv1h firmware | ||
qualcomm qamsrv1h | ||
All of | ||
qualcomm qam8775p Firmware | ||
qualcomm qam8775p | ||
All of | ||
qualcomm qam8650p Firmware | ||
qualcomm qam8650p | ||
All of | ||
qualcomm qam8255p firmware | ||
qualcomm qam8255p |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23378 is classified as a significant vulnerability due to potential memory corruption issues.
To fix CVE-2024-23378, ensure you update your Qualcomm firmware to the latest version recommended by Qualcomm.
CVE-2024-23378 affects various Qualcomm firmware versions, including those for Snapdragon and SA series products.
CVE-2024-23378 might lead to unstable audio playback or recording due to memory corruption during IOCTL calls.
CVE-2024-23378 is primarily a local vulnerability, focusing on user space manipulation during audio functions.