CVE-2024-23378

Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
qualcommsrv1m_firmware
-
qualcommsrv1h_firmware
-
qualcommsnapdragon_auto_5g_modem-rf_gen_2_firmware
-
qualcommsa9000p_firmware
-
qualcommsa8775p_firmware
-
qualcommsa8770p_firmware
-
qualcommsa8650p_firmware
-
qualcommsa8620p_firmware
-
qualcommsa8255p_firmware
-
qualcommsa7775p_firmware
-
qualcommsa7255p_firmware
-
qualcommqca6698aq_firmware
-
qualcommqca6584au_firmware
-
qualcommqamsrv1m_firmware
-
qualcommqamsrv1h_firmware
-
qualcommqam8775p_firmware
-
qualcommqam8650p_firmware
-
qualcommqam8255p_firmware
-
𝑥
= Vulnerable software versions