First published: Mon Nov 04 2024(Updated: )
memory corruption when WiFi display APIs are invoked with large random inputs.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm WSA8835 | ||
Qualcomm WSA8835 Firmware | ||
All of | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8830 | ||
All of | ||
Qualcomm WCN3660B | ||
Qualcomm WCN3660B Firmware | ||
All of | ||
Qualcomm WCN3620 Firmware | ||
Qualcomm WCN3620 Firmware | ||
All of | ||
Qualcomm WCD9380 | ||
Qualcomm WCD9380 Firmware | ||
All of | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Platform | ||
Qualcomm Snapdragon 8 Gen 1 Mobile Firmware | ||
All of | ||
Qualcomm Snapdragon 429 Mobile Platform Firmware | ||
Qualcomm Snapdragon 429 Mobile Platform | ||
All of | ||
Qualcomm SDM429W | ||
qualcomm SDM429W firmware | ||
All of | ||
Qualcomm Fastconnect 7800 Firmware | ||
Qualcomm Fastconnect 7800 Firmware | ||
All of | ||
Qualcomm FastConnect 6900 Firmware | ||
Qualcomm Fastconnect 6900 Firmware |
https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23386 is a critical severity vulnerability due to memory corruption that can lead to potential system exploitation.
To mitigate CVE-2024-23386, users should update the affected Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2024-23386 affects various Qualcomm firmware implementations, including Wsa8835, Wsa8830, and Wcn3660b, among others.
Exploitation of CVE-2024-23386 can result in unauthorized memory access, leading to crashes or execution of malicious code.
Users can check their device’s firmware version against the list of affected Qualcomm products to ascertain vulnerability to CVE-2024-23386.