7.8

CVE-2024-43061

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

Data is provided by the National Vulnerability Database (NVD)
QualcommQam8295p Firmware Version-
   QualcommQam8295p
QualcommQca6696 Firmware Version-
   QualcommQca6696
QualcommQca9367 Firmware Version-
   QualcommQca9367
QualcommQca9377 Firmware Version-
   QualcommQca9377
QualcommQcs8550 Firmware Version-
   QualcommQcs8550
QualcommSa6145p Firmware Version-
   QualcommSa6145p
QualcommSa6150p Firmware Version-
   QualcommSa6150p
QualcommSa6155p Firmware Version-
   QualcommSa6155p
QualcommSa8145p Firmware Version-
   QualcommSa8145p
QualcommSa8150p Firmware Version-
   QualcommSa8150p
QualcommSa8155p Firmware Version-
   QualcommSa8155p
QualcommSa8195p Firmware Version-
   QualcommSa8195p
QualcommSa8295p Firmware Version-
   QualcommSa8295p
QualcommSa8530p Firmware Version-
   QualcommSa8530p
QualcommSa8540p Firmware Version-
   QualcommSa8540p
QualcommSa9000p Firmware Version-
   QualcommSa9000p
QualcommSdm429w Firmware Version-
   QualcommSdm429w
QualcommSxr2230p Firmware Version-
   QualcommSxr2230p
QualcommSxr2250p Firmware Version-
   QualcommSxr2250p
QualcommWcd9380 Firmware Version-
   QualcommWcd9380
QualcommWcd9385 Firmware Version-
   QualcommWcd9385
QualcommWcn3620 Firmware Version-
   QualcommWcn3620
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b
QualcommWsa8830 Firmware Version-
   QualcommWsa8830
QualcommWsa8832 Firmware Version-
   QualcommWsa8832
QualcommWsa8835 Firmware Version-
   QualcommWsa8835
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.061
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.