Description

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.

INFO

Published Date :

2024-11-04T10:04:32.745Z

Last Modified :

2024-11-08T04:55:09.987Z

Source :

qualcomm
AFFECTED PRODUCTS

The following products are affected by CVE-2024-23377 vulnerability.

Vendors Products
Qualcomm
  • Fastconnect 6900
  • Fastconnect 6900 Firmware
  • Fastconnect 7800
  • Fastconnect 7800 Firmware
  • Qca6391
  • Qca6391 Firmware
  • Qcm8550
  • Qcm8550 Firmware
  • Qcs7230
  • Qcs7230 Firmware
  • Qcs8250
  • Qcs8250 Firmware
  • Qcs8550
  • Qcs8550 Firmware
  • Qualcomm Video Collaboration Vc5 Platform Firmware
  • Sd 8 Gen1 5g
  • Sd 8 Gen1 5g Firmware
  • Sg8275
  • Sg8275 Firmware
  • Sg8275p
  • Sg8275p Firmware
  • Sm7525
  • Sm7525 Firmware
  • Sm7550
  • Sm7550 Firmware
  • Sm8550p
  • Sm8550p Firmware
  • Snapdragon 8\+ Gen 2 Mobile Platform
  • Snapdragon 8\+ Gen 2 Mobile Platform Firmware
  • Snapdragon 8 Gen 2 Mobile Platform
  • Snapdragon 8 Gen 2 Mobile Platform Firmware
  • Snapdragon Ar2 Gen 1 Platform
  • Snapdragon Ar2 Gen 1 Platform Firmware
  • Ssg2115p
  • Ssg2115p Firmware
  • Ssg2125p
  • Ssg2125p Firmware
  • Sxr1230p
  • Sxr1230p Firmware
  • Sxr2230p
  • Sxr2230p Firmware
  • Sxr2250p
  • Sxr2250p Firmware
  • Video Collaboration Vc5 Platform
  • Video Collaboration Vc5 Platform Firmware
  • Wcd9370
  • Wcd9370 Firmware
  • Wcd9371
  • Wcd9371 Firmware
  • Wcd9375
  • Wcd9375 Firmware
  • Wcd9378
  • Wcd9378 Firmware
  • Wcd9380
  • Wcd9380 Firmware
  • Wcd9385
  • Wcd9385 Firmware
  • Wcd9390
  • Wcd9390 Firmware
  • Wcd9395
  • Wcd9395 Firmware
  • Wcn6650
  • Wcn6650 Firmware
  • Wcn6755
  • Wcn6755 Firmware
  • Wcn7880
  • Wcn7880 Firmware
  • Wsa8830
  • Wsa8830 Firmware
  • Wsa8832
  • Wsa8832 Firmware
  • Wsa8835
  • Wsa8835 Firmware
  • Wsa8840
  • Wsa8840 Firmware
  • Wsa8845
  • Wsa8845 Firmware
  • Wsa8845h
  • Wsa8845h Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-23377.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact