First published: Mon Dec 02 2024(Updated: )
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
qualcomm qam8255p firmware | ||
qualcomm qam8255p | ||
All of | ||
qualcomm qam8650p Firmware | ||
qualcomm qam8650p | ||
All of | ||
qualcomm qam8775p Firmware | ||
qualcomm qam8775p | ||
All of | ||
qualcomm qamsrv1h firmware | ||
qualcomm qamsrv1h | ||
All of | ||
qualcomm qamsrv1m firmware | ||
qualcomm qamsrv1m | ||
All of | ||
qualcomm sa7255p firmware | ||
Qualcomm Sa7255p | ||
All of | ||
Qualcomm Sa7775p Firmware | ||
Qualcomm Sa7775p | ||
All of | ||
Qualcomm Sa8255p Firmware | ||
Qualcomm Sa8255p | ||
All of | ||
Qualcomm Sa8620p Firmware | ||
Qualcomm Sa8620p | ||
All of | ||
Qualcomm Sa8650p Firmware | ||
Qualcomm Sa8650p | ||
All of | ||
Qualcomm Sa8770p Firmware | ||
Qualcomm Sa8770p | ||
All of | ||
Qualcomm Sa8775p Firmware | ||
Qualcomm Sa8775p | ||
All of | ||
qualcomm sa9000p firmware | ||
qualcomm sa9000p | ||
All of | ||
Qualcomm Snapdragon W5\+ Gen 1 Wearable Platform Firmware | ||
Qualcomm Snapdragon W5\+ Gen 1 Wearable Platform | ||
All of | ||
Qualcomm Srv1h Firmware | ||
Qualcomm Srv1h | ||
All of | ||
Qualcomm Srv1m Firmware | ||
Qualcomm Srv1m | ||
All of | ||
qualcomm sw5100 firmware | ||
qualcomm sw5100 | ||
All of | ||
qualcomm sw5100p firmware | ||
qualcomm sw5100p | ||
All of | ||
qualcomm wcn3980 firmware | ||
Qualcomm Wcn3980 | ||
All of | ||
qualcomm wcn3988 firmware | ||
Qualcomm WCN3988 | ||
All of | ||
qualcomm wsa8830 firmware | ||
qualcomm wsa8830 | ||
All of | ||
qualcomm wsa8835 firmware | ||
qualcomm wsa8835 |
https://docs.qualcomm.com/product/publicresources/securitybulletin/december-2024-bulletin.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33039 has a high severity due to the potential for memory corruption vulnerabilities.
To fix CVE-2024-33039, ensure that your firmware is updated to the latest version provided by Qualcomm.
CVE-2024-33039 affects multiple Qualcomm firmware products, including QAM8255P, QAM8650P, and QAM8775P.
Yes, CVE-2024-33039 can potentially be exploited remotely if an attacker manipulates the PAL service API.
If using affected Qualcomm devices, it is recommended to monitor for firmware updates and apply them as soon as possible.