CVE-2024-33030: Buffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in Performance
Published Nov 4, 2024
·Updated
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
Affected Software
44 affected components
All of the following
Qualcomm Wsa8835 Firmware
Qualcomm Wsa8835
All of the following
Qualcomm Wsa8830 Firmware
Qualcomm Wsa8830
All of the following
Qualcomm Wcd9380 Firmware
Qualcomm Wcd9380
All of the following
Qualcomm Wcd9340 Firmware
Qualcomm Wcd9340
All of the following
Qualcomm Snapdragon X75 5g Modem-rf System Firmware
Qualcomm Snapdragon X75 5g Modem-rf System
All of the following
Qualcomm Snapdragon X72 5g Modem-rf System Firmware
Qualcomm Snapdragon X72 5g Modem-rf System
All of the following
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2 Firmware
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2
All of the following
Qualcomm Snapdragon 8 Gen 1 Mobile Platform Firmware
Qualcomm Snapdragon 8 Gen 1 Mobile Platform
All of the following
Qualcomm Qfw7124 Firmware
Qualcomm Qfw7124
All of the following
Qualcomm Qfw7114 Firmware
Qualcomm Qfw7114
All of the following
Qualcomm Qcn6274 Firmware
Qualcomm Qcn6274
All of the following
Qualcomm Qcn6224 Firmware
Qualcomm Qcn6224
All of the following
Qualcomm Qcc710 Firmware
Qualcomm Qcc710
All of the following
Qualcomm Qca9377 Firmware
Qualcomm QCA9377
All of the following
Qualcomm Qca9367 Firmware
Qualcomm Qca9367
All of the following
Qualcomm Qca8337 Firmware
Qualcomm Qca8337
All of the following
Qualcomm Qca8081 Firmware
Qualcomm QCA8081
All of the following
Qualcomm Qca6698aq Firmware
Qualcomm Qca6698aq
All of the following
Qualcomm Qca6584au Firmware
Qualcomm QCA6584AU
All of the following
Qualcomm Fastconnect 7800 Firmware
Qualcomm Fastconnect 7800
All of the following
Qualcomm Fastconnect 6900 Firmware
Qualcomm Fastconnect 6900
All of the following
Qualcomm Ar8035 Firmware
Qualcomm Ar8035
Remediation
Event History
Nov 4, 2024
CVE Published
via MITRE·10:04 AM
Data Sourced
via MITRE·10:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33030?
CVE-2024-33030 is classified as a high severity vulnerability due to potential memory corruption issues.
2
How do I fix CVE-2024-33030?
To fix CVE-2024-33030, update the affected Qualcomm firmware to the latest version that addresses this vulnerability.
3
Which Qualcomm devices are affected by CVE-2024-33030?
CVE-2024-33030 affects various Qualcomm firmware including Wsa8835, Wsa8830, and several Snapdragon models among others.
4
What are the potential impacts of CVE-2024-33030?
The impact of CVE-2024-33030 includes the possibility of system instability and exploitation through memory corruption.
5
When was CVE-2024-33030 published?
CVE-2024-33030 was published in November 2024 following a security bulletin by Qualcomm.