CVE-2024-23378

EUVD-2024-20882
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
qualcommsrv1m_firmware
-
qualcommsrv1h_firmware
-
qualcommsnapdragon_auto_5g_modem-rf_gen_2_firmware
-
qualcommsa9000p_firmware
-
qualcommsa8775p_firmware
-
qualcommsa8770p_firmware
-
qualcommsa8650p_firmware
-
qualcommsa8620p_firmware
-
qualcommsa8255p_firmware
-
qualcommsa7775p_firmware
-
qualcommsa7255p_firmware
-
qualcommqca6698aq_firmware
-
qualcommqca6584au_firmware
-
qualcommqamsrv1m_firmware
-
qualcommqamsrv1h_firmware
-
qualcommqam8775p_firmware
-
qualcommqam8650p_firmware
-
qualcommqam8255p_firmware
-
𝑥
= Vulnerable software versions