CVE-2024-23378

EUVD-2024-20882
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
qualcommsrv1m_firmware
-
qualcommsrv1h_firmware
-
qualcommsnapdragon_auto_5g_modem-rf_gen_2_firmware
-
qualcommsa9000p_firmware
-
qualcommsa8775p_firmware
-
qualcommsa8770p_firmware
-
qualcommsa8650p_firmware
-
qualcommsa8620p_firmware
-
qualcommsa8255p_firmware
-
qualcommsa7775p_firmware
-
qualcommsa7255p_firmware
-
qualcommqca6698aq_firmware
-
qualcommqca6584au_firmware
-
qualcommqamsrv1m_firmware
-
qualcommqamsrv1h_firmware
-
qualcommqam8775p_firmware
-
qualcommqam8650p_firmware
-
qualcommqam8255p_firmware
-
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qualcommqam8255p_firmware
𝑥
≤ *
ADP
qualcommqam8650p_firmware
𝑥
≤ *
ADP
qualcommqam8775p_firmware
𝑥
≤ *
ADP
qualcommqamsrv1h_firmware
𝑥
≤ *
ADP
qualcommqamsrv1m_firmware
𝑥
≤ *
ADP
qualcommqca6584au_firmware
𝑥
≤ *
ADP
qualcommqca6698aq_firmware
𝑥
≤ *
ADP
qualcommsa7255p_firmware
𝑥
≤ *
ADP
qualcommsa7775p_firmware
𝑥
≤ *
ADP
qualcommsa8255p_firmware
𝑥
≤ *
ADP
qualcommsa8620p_firmware
𝑥
≤ *
ADP
qualcommsa8650p_firmware
𝑥
≤ *
ADP
qualcommsa8770p_firmware
𝑥
≤ *
ADP
qualcommsa8775p_firmware
𝑥
≤ *
ADP
qualcommsa9000p_firmware
𝑥
≤ *
ADP
qualcommsnapdragon_auto_5g_modem-rf_gen_2_firmware
𝑥
≤ *
ADP
qualcommsrv1h_firmware
𝑥
≤ *
ADP
qualcommsrv1m_firmware
𝑥
≤ *
ADP