First published: Mon Nov 04 2024(Updated: )
memory corruption when WiFi display APIs are invoked with large random inputs.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm Wsa8835 Firmware | ||
Qualcomm Wsa8835 | ||
All of | ||
Qualcomm Wsa8830 Firmware | ||
Qualcomm Wsa8830 | ||
All of | ||
Qualcomm Wcn3660b Firmware | ||
Qualcomm Wcn3660b | ||
All of | ||
Qualcomm Wcn3620 Firmware | ||
Qualcomm Wcn3620 | ||
All of | ||
Qualcomm Wcd9380 Firmware | ||
Qualcomm Wcd9380 | ||
All of | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Platform Firmware | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Platform | ||
All of | ||
Qualcomm Snapdragon 429 Mobile Platform Firmware | ||
Qualcomm Snapdragon 429 Mobile Platform | ||
All of | ||
Qualcomm Sdm429w Firmware | ||
Qualcomm Sdm429w | ||
All of | ||
Qualcomm Fastconnect 7800 Firmware | ||
Qualcomm Fastconnect 7800 | ||
All of | ||
Qualcomm Fastconnect 6900 Firmware | ||
Qualcomm Fastconnect 6900 |
https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23386 is a critical severity vulnerability due to memory corruption that can lead to potential system exploitation.
To mitigate CVE-2024-23386, users should update the affected Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2024-23386 affects various Qualcomm firmware implementations, including Wsa8835, Wsa8830, and Wcn3660b, among others.
Exploitation of CVE-2024-23386 can result in unauthorized memory access, leading to crashes or execution of malicious code.
Users can check their device’s firmware version against the list of affected Qualcomm products to ascertain vulnerability to CVE-2024-23386.