First published: Mon Dec 02 2024(Updated: )
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm QAM8255P | ||
Qualcomm QAM8255P Firmware | ||
All of | ||
Qualcomm QAM8650P Firmware | ||
Qualcomm QAM8650P Firmware | ||
All of | ||
Qualcomm QAM8775P | ||
Qualcomm QAM8775P Firmware | ||
All of | ||
Qualcomm SRV1H Firmware | ||
Qualcomm QAMSRV1H Firmware | ||
All of | ||
Qualcomm QAMSRV1M Firmware | ||
Qualcomm QAMSRV1M Firmware | ||
All of | ||
Qualcomm SA7255P | ||
qualcomm sa7255p firmware | ||
All of | ||
Qualcomm SA7775P Firmware | ||
Qualcomm SA7775P Firmware | ||
All of | ||
Qualcomm SA8255P Firmware | ||
Qualcomm SA8255P Firmware | ||
All of | ||
Qualcomm SA8620P | ||
Qualcomm SA8620P | ||
All of | ||
Qualcomm SA8650P | ||
Qualcomm SA8650P | ||
All of | ||
Qualcomm SA8770P Firmware | ||
qualcomm sa8770p firmware | ||
All of | ||
Qualcomm SA8775P | ||
Qualcomm SA8775P | ||
All of | ||
Qualcomm SA9000P Firmware | ||
Qualcomm SA9000P Firmware | ||
All of | ||
Qualcomm Snapdragon W5+ Gen 1 Wearable Platform Firmware | ||
Qualcomm Snapdragon W5+ Gen 1 Wearable Platform | ||
All of | ||
Qualcomm SRV1H | ||
Qualcomm SRV1H Firmware | ||
All of | ||
Qualcomm SRV1M | ||
Qualcomm SRV1M Firmware | ||
All of | ||
Qualcomm SW5100P | ||
Qualcomm SW5100P | ||
All of | ||
Qualcomm SW5100 Firmware | ||
Qualcomm SW5100 Firmware | ||
All of | ||
Qualcomm Wcn3980 | ||
Qualcomm WCN3980 | ||
All of | ||
Qualcomm WCN3988 Firmware | ||
Qualcomm WCN3988 Firmware | ||
All of | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8830 | ||
All of | ||
Qualcomm WSA8835 | ||
Qualcomm WSA8835 Firmware |
https://docs.qualcomm.com/product/publicresources/securitybulletin/december-2024-bulletin.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33039 has a high severity due to the potential for memory corruption vulnerabilities.
To fix CVE-2024-33039, ensure that your firmware is updated to the latest version provided by Qualcomm.
CVE-2024-33039 affects multiple Qualcomm firmware products, including QAM8255P, QAM8650P, and QAM8775P.
Yes, CVE-2024-33039 can potentially be exploited remotely if an attacker manipulates the PAL service API.
If using affected Qualcomm devices, it is recommended to monitor for firmware updates and apply them as soon as possible.