CVE-2024-45565: Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver
Published May 6, 2025
·Updated
Memory corruption when blob structure is modified by user-space after kernel verification.
Affected Software
8 affected components
All of the following
QUALCOMM Sdm429w Firmware
QUALCOMM Sdm429w
All of the following
QUALCOMM Snapdragon 429 Mobile Firmware
QUALCOMM Snapdragon 429 Mobile
All of the following
QUALCOMM Wcn3620 Firmware
QUALCOMM Wcn3620
All of the following
Qualcomm Wcn3660b Firmware
QUALCOMM Wcn3660b
Remediation
Event History
May 6, 2025
CVE Published
via MITRE·08:31 AM
Data Sourced
via MITRE·08:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45565?
CVE-2024-45565 is classified as a high severity vulnerability due to memory corruption issues that could lead to arbitrary code execution.
2
How do I fix CVE-2024-45565?
To mitigate CVE-2024-45565, apply the latest firmware updates provided by Qualcomm for affected devices.
3
Which devices are affected by CVE-2024-45565?
CVE-2024-45565 affects Qualcomm SDM429W, Snapdragon 429 Mobile, WCN3620, and WCN3660B firmware.
4
What type of vulnerability is CVE-2024-45565?
CVE-2024-45565 is a memory corruption vulnerability that arises from user-space modifications to blob structures after kernel verification.
5
Can CVE-2024-45565 lead to data breaches?
Yes, if exploited, CVE-2024-45565 could potentially lead to data breaches through arbitrary code execution.