Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23370


Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.


Published

2024-10-07T13:15:10.927

Last Modified

2024-10-16T20:27:07.517

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-416
  • Type: Primary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm wsa8835_firmware - Yes
Hardware qualcomm wsa8835 - No
Operating System qualcomm wsa8830_firmware - Yes
Hardware qualcomm wsa8830 - No
Operating System qualcomm wcn3988_firmware - Yes
Hardware qualcomm wcn3988 - No
Operating System qualcomm wcn3980_firmware - Yes
Hardware qualcomm wcn3980 - No
Operating System qualcomm sw5100p_firmware - Yes
Hardware qualcomm sw5100p - No
Operating System qualcomm sw5100_firmware - Yes
Hardware qualcomm sw5100 - No
Operating System qualcomm snapdragon_auto_5g_modem-rf_gen_2_firmware - Yes
Hardware qualcomm snapdragon_auto_5g_modem-rf_gen_2 - No
Operating System qualcomm qca9377_firmware - Yes
Hardware qualcomm qca9377 - No
Operating System qualcomm qca9367_firmware - Yes
Hardware qualcomm qca9367 - No
Operating System qualcomm qca6698aq_firmware - Yes
Hardware qualcomm qca6698aq - No
Operating System qualcomm qca6584au_firmware - Yes
Hardware qualcomm qca6584au - No

References