First published: Mon Dec 02 2024(Updated: )
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
qualcomm fastconnect 6800 Firmware | ||
qualcomm fastconnect 6800 | ||
All of | ||
qualcomm fastconnect 6900 Firmware | ||
qualcomm fastconnect 6900 | ||
All of | ||
qualcomm fastconnect 7800 firmware | ||
qualcomm fastconnect 7800 | ||
All of | ||
qualcomm qam8255p firmware | ||
qualcomm qam8255p | ||
All of | ||
qualcomm qca6391 firmware | ||
qualcomm qca6391 | ||
All of | ||
qualcomm qca6426 firmware | ||
qualcomm qca6426 | ||
All of | ||
qualcomm qca6436 firmware | ||
qualcomm qca6436 | ||
All of | ||
qualcomm qca6595au firmware | ||
qualcomm qca6595au | ||
All of | ||
qualcomm qca6678aq firmware | ||
qualcomm qca6678aq | ||
All of | ||
qualcomm sa8255p firmware | ||
qualcomm sa8255p | ||
All of | ||
qualcomm sd865 5g firmware | ||
qualcomm sd865 5g | ||
All of | ||
qualcomm snapdragon 8 gen 1 mobile platform firmware | ||
qualcomm snapdragon 8 gen 1 mobile platform | ||
All of | ||
qualcomm snapdragon 865 5g mobile platform firmware | ||
qualcomm snapdragon 865 5g mobile platform | ||
All of | ||
qualcomm snapdragon 865\+ 5g mobile platform firmware | ||
qualcomm snapdragon 865\+ 5g mobile platform | ||
All of | ||
qualcomm snapdragon 870 5g mobile platform firmware | ||
qualcomm snapdragon 870 5g mobile platform | ||
All of | ||
qualcomm snapdragon w5\+ gen 1 wearable platform firmware | ||
qualcomm snapdragon w5\+ gen 1 wearable platform | ||
All of | ||
qualcomm snapdragon x55 5g modem-rf system firmware | ||
qualcomm snapdragon x55 5g modem-rf system | ||
All of | ||
qualcomm snapdragon xr2 5g platform firmware | ||
qualcomm snapdragon xr2 5g platform | ||
All of | ||
qualcomm sw5100 firmware | ||
qualcomm sw5100 | ||
All of | ||
qualcomm sw5100p firmware | ||
qualcomm sw5100p | ||
All of | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 | ||
All of | ||
qualcomm wcd9380 firmware | ||
qualcomm wcd9380 | ||
All of | ||
Qualcomm wcn3660b firmware | ||
Qualcomm wcn3660b | ||
All of | ||
Qualcomm wcn3680b firmware | ||
Qualcomm wcn3680b | ||
All of | ||
qualcomm wcn3980 firmware | ||
Qualcomm Wcn3980 | ||
All of | ||
qualcomm wcn3988 firmware | ||
Qualcomm WCN3988 | ||
All of | ||
qualcomm wsa8810 firmware | ||
qualcomm wsa8810 | ||
All of | ||
qualcomm wsa8815 firmware | ||
qualcomm wsa8815 | ||
All of | ||
qualcomm wsa8830 firmware | ||
qualcomm wsa8830 | ||
All of | ||
qualcomm wsa8835 firmware | ||
qualcomm wsa8835 |
https://docs.qualcomm.com/product/publicresources/securitybulletin/december-2024-bulletin.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33040 has a high severity due to potential memory corruption leading to system instability and security breaches.
To fix CVE-2024-33040, apply the latest firmware updates provided by Qualcomm for the affected devices.
Devices affected by CVE-2024-33040 include various Qualcomm chipsets like FastConnect 6800, 6900, 7800, and others listed in the security advisory.
CVE-2024-33040 is a memory corruption vulnerability that occurs due to a race condition while releasing buffers from user space.
As of now, there is no public indication that CVE-2024-33040 is being actively exploited in the wild.