CVE-2024-33037: Buffer Over-read in Neural Processing Unit
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesnt validate the IPC message received from the firmware.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33037?
The severity of CVE-2024-33037 may vary based on its specific impact, but it is classified as an information disclosure vulnerability.
How do I fix CVE-2024-33037?
To fix CVE-2024-33037, ensure that you apply the latest firmware updates provided by Qualcomm for the affected devices.
What devices are affected by CVE-2024-33037?
CVE-2024-33037 affects various Qualcomm firmware versions and hardware including the c-v2x 9150, fastconnect series, qca series, and several others.
What type of vulnerability is CVE-2024-33037?
CVE-2024-33037 is an information disclosure vulnerability that stems from an unvalidated IPC message sent from the NPU firmware to its driver.
What could be the potential impact of CVE-2024-33037?
The potential impact of CVE-2024-33037 includes unauthorized access to sensitive information due to the improper validation of IPC messages.