First published: Mon Feb 03 2025(Updated: )
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
qualcomm fastconnect 6900 Firmware | ||
qualcomm fastconnect 6900 | ||
All of | ||
qualcomm fastconnect 7800 firmware | ||
qualcomm fastconnect 7800 | ||
All of | ||
qualcomm qcc2073 firmware | ||
qualcomm qcc2073 | ||
All of | ||
Qualcomm Qcc2076 Firmware | ||
Qualcomm Qcc2076 | ||
All of | ||
qualcomm sc8380xp firmware | ||
qualcomm sc8380xp | ||
All of | ||
qualcomm wcd9380 firmware | ||
qualcomm wcd9380 | ||
All of | ||
qualcomm wcd9385 firmware | ||
qualcomm wcd9385 | ||
All of | ||
qualcomm wsa8840 firmware | ||
qualcomm wsa8840 | ||
All of | ||
qualcomm wsa8845 firmware | ||
qualcomm wsa8845 | ||
All of | ||
qualcomm wsa8845h firmware | ||
Qualcomm Wsa8845h |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49840 has been classified with a high severity due to its potential for memory corruption vulnerabilities.
To fix CVE-2024-49840, users should update their Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2024-49840 affects various Qualcomm firmware products, including FastConnect 6900, FastConnect 7800, QCC2073, QCC2076, and others.
CVE-2024-49840 is caused by memory corruption that occurs when invoking IOCTL calls from user-space.
Currently, there are no known effective workarounds for CVE-2024-49840 other than updating to a patched firmware version.