First published: Mon Feb 03 2025(Updated: )
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm FastConnect 6900 Firmware | ||
Qualcomm Fastconnect 6900 Firmware | ||
All of | ||
Qualcomm Fastconnect 7800 Firmware | ||
Qualcomm Fastconnect 7800 Firmware | ||
All of | ||
Qualcomm QCC2073 | ||
qualcomm qcc2073 firmware | ||
All of | ||
Qualcomm Qcc2076 Firmware | ||
Qualcomm Qcc2076 Firmware | ||
All of | ||
Qualcomm SC8380XP | ||
qualcomm sc8380xp firmware | ||
All of | ||
Qualcomm WCD9380 | ||
Qualcomm WCD9380 Firmware | ||
All of | ||
Qualcomm WCD9385 | ||
Qualcomm WCD9385 Firmware | ||
All of | ||
Qualcomm WSA8840 Firmware | ||
Qualcomm WSA8840 Firmware | ||
All of | ||
Qualcomm WSA8845H | ||
Qualcomm WSA8845 Firmware | ||
All of | ||
Qualcomm WSA8845H | ||
Qualcomm WSA8845H Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49840 has been classified with a high severity due to its potential for memory corruption vulnerabilities.
To fix CVE-2024-49840, users should update their Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2024-49840 affects various Qualcomm firmware products, including FastConnect 6900, FastConnect 7800, QCC2073, QCC2076, and others.
CVE-2024-49840 is caused by memory corruption that occurs when invoking IOCTL calls from user-space.
Currently, there are no known effective workarounds for CVE-2024-49840 other than updating to a patched firmware version.