CVE-2024-23379: Double Free in DSP Services
Published Oct 7, 2024
·Updated
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
Affected Software
68 affected components
All of the following
Qualcomm Wsa8835 Firmware
Qualcomm Wsa8835
All of the following
Qualcomm Wsa8830 Firmware
Qualcomm Wsa8830
All of the following
Qualcomm Wsa8815 Firmware
Qualcomm Wsa8815
All of the following
Qualcomm Wsa8810 Firmware
Qualcomm Wsa8810
All of the following
Qualcomm Wcn3990 Firmware
Qualcomm Wcn3990
All of the following
Qualcomm Wcd9380 Firmware
Qualcomm Wcd9380
All of the following
Qualcomm Wcd9341 Firmware
Qualcomm Wcd9341
All of the following
Qualcomm Wcd9340 Firmware
Qualcomm Wcd9340
All of the following
Qualcomm Wcd9335 Firmware
Qualcomm Wcd9335
All of the following
Qualcomm Srv1m Firmware
Qualcomm Srv1m
All of the following
Qualcomm Srv1h Firmware
Qualcomm Srv1h
All of the following
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2 Firmware
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2
All of the following
Qualcomm Snapdragon 835 Mobile Pc Platform Firmware
Qualcomm Snapdragon 835 Mobile Pc Platform
All of the following
Qualcomm Snapdragon 8 Gen 1 Mobile Platform Firmware
Qualcomm Snapdragon 8 Gen 1 Mobile Platform
All of the following
Qualcomm Sd835 Firmware
Qualcomm Sd835
All of the following
Qualcomm Sa9000p Firmware
Qualcomm Sa9000p
All of the following
Qualcomm Sa8775p Firmware
Qualcomm Sa8775p
All of the following
Qualcomm Sa8770p Firmware
Qualcomm Sa8770p
All of the following
Qualcomm Sa8650p Firmware
Qualcomm Sa8650p
All of the following
Qualcomm Sa8620p Firmware
Qualcomm Sa8620p
All of the following
Qualcomm Sa8255p Firmware
Qualcomm Sa8255p
All of the following
Qualcomm Sa7775p Firmware
Qualcomm Sa7775p
All of the following
Qualcomm Sa7255p Firmware
Qualcomm Sa7255p
All of the following
Qualcomm Qca6698aq Firmware
Qualcomm Qca6698aq
All of the following
Qualcomm Qca6584au Firmware
Qualcomm QCA6584AU
All of the following
Qualcomm Qca6320 Firmware
Qualcomm Qca6320
All of the following
Qualcomm Qca6310 Firmware
Qualcomm Qca6310
All of the following
Qualcomm Qamsrv1m Firmware
Qualcomm Qamsrv1m
All of the following
Qualcomm Qamsrv1h Firmware
Qualcomm Qamsrv1h
All of the following
Qualcomm Qam8775p Firmware
Qualcomm Qam8775p
All of the following
Qualcomm Qam8650p Firmware
Qualcomm Qam8650p
All of the following
Qualcomm Qam8255p Firmware
Qualcomm Qam8255p
All of the following
Qualcomm Fastconnect 7800 Firmware
Qualcomm Fastconnect 7800
All of the following
Qualcomm Fastconnect 6900 Firmware
Qualcomm Fastconnect 6900
Event History
Oct 7, 2024
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23379?
CVE-2024-23379 is classified as a critical memory corruption vulnerability in Qualcomm firmware.
2
How does CVE-2024-23379 affect vulnerable devices?
CVE-2024-23379 can lead to memory corruption when two threads attempt to free the same fastrpc map concurrently.
3
Which devices are affected by CVE-2024-23379?
CVE-2024-23379 affects several Qualcomm firmware variants including Wsa8835, Wsa8830, and Wcd9380 among others.
4
What is the recommended action to mitigate CVE-2024-23379?
To mitigate CVE-2024-23379, users should apply the latest firmware updates provided by Qualcomm.
5
Where can I find more information about CVE-2024-23379?
Further information regarding CVE-2024-23379 can be found in Qualcomm's security bulletins released in October 2024.