First published: Mon Feb 03 2025(Updated: )
Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
qualcomm fastconnect 6900 Firmware | ||
qualcomm fastconnect 6900 | ||
All of | ||
qualcomm fastconnect 7800 firmware | ||
qualcomm fastconnect 7800 | ||
All of | ||
qualcomm qcm8550 firmware | ||
qualcomm qcm8550 | ||
All of | ||
Qualcomm qcs6490 firmware | ||
Qualcomm qcs6490 | ||
All of | ||
qualcomm qcs8550 firmware | ||
qualcomm qcs8550 | ||
All of | ||
qualcomm video collaboration vc3 firmware | ||
qualcomm video collaboration vc3 | ||
All of | ||
qualcomm sg8275p firmware | ||
qualcomm sg8275p | ||
All of | ||
qualcomm sm8550p firmware | ||
qualcomm sm8550p | ||
All of | ||
Qualcomm Snapdragon 8 Gen 2 Firmware | ||
Qualcomm Snapdragon 8 Gen 2 | ||
All of | ||
Qualcomm Snapdragon 8 Gen 3 Firmware | ||
Qualcomm Snapdragon 8 Gen 3 | ||
All of | ||
qualcomm snapdragon 8\+ gen 2 mobile firmware | ||
qualcomm snapdragon 8\+ gen 2 mobile | ||
All of | ||
qualcomm wcd9380 firmware | ||
qualcomm wcd9380 | ||
All of | ||
qualcomm wcd9385 firmware | ||
qualcomm wcd9385 | ||
All of | ||
qualcomm wcd9390 firmware | ||
qualcomm wcd9390 | ||
All of | ||
qualcomm wcd9395 firmware | ||
qualcomm wcd9395 | ||
All of | ||
qualcomm wsa8840 firmware | ||
qualcomm wsa8840 | ||
All of | ||
qualcomm wsa8845 firmware | ||
qualcomm wsa8845 | ||
All of | ||
qualcomm wsa8845h firmware | ||
Qualcomm Wsa8845h |
https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38411 is categorized with a severity level that indicates potential risk to the integrity of systems using affected Qualcomm firmware.
To mitigate CVE-2024-38411, it is recommended to apply the latest firmware updates provided by Qualcomm for the affected devices.
CVE-2024-38411 affects various Qualcomm firmware versions, including the Fastconnect series and Snapdragon series among others.
The criticality of CVE-2024-38411 largely depends on the specific device and its use case.
CVE-2024-38411 is a memory corruption vulnerability that arises from improper handling of IOCTL calls between user-space and kernel-space.