6.7

CVE-2024-23377

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.

Data is provided by the National Vulnerability Database (NVD)
QualcommWsa8845h Firmware Version-
   QualcommWsa8845h Version-
QualcommWsa8845 Firmware Version-
   QualcommWsa8845 Version-
QualcommWsa8840 Firmware Version-
   QualcommWsa8840 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
QualcommWsa8832 Firmware Version-
   QualcommWsa8832 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWcn7880 Firmware Version-
   QualcommWcn7880 Version-
QualcommWcn6755 Firmware Version-
   QualcommWcn6755 Version-
QualcommWcn6650 Firmware Version-
   QualcommWcn6650 Version-
QualcommWcd9395 Firmware Version-
   QualcommWcd9395 Version-
QualcommWcd9390 Firmware Version-
   QualcommWcd9390 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9378 Firmware Version-
   QualcommWcd9378 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9371 Firmware Version-
   QualcommWcd9371 Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommSxr2250p Firmware Version-
   QualcommSxr2250p Version-
QualcommSxr2230p Firmware Version-
   QualcommSxr2230p Version-
QualcommSxr1230p Firmware Version-
   QualcommSxr1230p Version-
QualcommSsg2125p Firmware Version-
   QualcommSsg2125p Version-
QualcommSsg2115p Firmware Version-
   QualcommSsg2115p Version-
QualcommSm8550p Firmware Version-
   QualcommSm8550p Version-
QualcommSm7550 Firmware Version-
   QualcommSm7550 Version-
QualcommSm7525 Firmware Version-
   QualcommSm7525 Version-
QualcommSg8275p Firmware Version-
   QualcommSg8275p Version-
QualcommSg8275 Firmware Version-
   QualcommSg8275 Version-
QualcommSd 8 Gen1 5g Firmware Version-
   QualcommSd 8 Gen1 5g Version-
QualcommQcs8550 Firmware Version-
   QualcommQcs8550 Version-
QualcommQcs8250 Firmware Version-
   QualcommQcs8250 Version-
QualcommQcs7230 Firmware Version-
   QualcommQcs7230 Version-
QualcommQcm8550 Firmware Version-
   QualcommQcm8550 Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.066
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-823 Use of Out-of-range Pointer Offset

The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.