7.8

CVE-2024-53032

Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive OS Platform

Memory corruption may occur in keyboard virtual device due to guest VM interaction.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommQam8255p Firmware Version-
   QualcommQam8255p
QualcommQam8295p Firmware Version-
   QualcommQam8295p
QualcommQam8620p Firmware Version-
   QualcommQam8620p
QualcommQam8650p Firmware Version-
   QualcommQam8650p
QualcommQam8775p Firmware Version-
   QualcommQam8775p
QualcommQamsrv1h Firmware Version-
   QualcommQamsrv1h
QualcommQamsrv1m Firmware Version-
   QualcommQamsrv1m
QualcommQca6595 Firmware Version-
   QualcommQca6595
QualcommQca6696 Firmware Version-
   QualcommQca6696
QualcommSa7255p Firmware Version-
   QualcommSa7255p
QualcommSa7775p Firmware Version-
   QualcommSa7775p
QualcommSa8255p Firmware Version-
   QualcommSa8255p
QualcommSa8295p Firmware Version-
   QualcommSa8295p
QualcommSa8540p Firmware Version-
   QualcommSa8540p
QualcommSa8620p Firmware Version-
   QualcommSa8620p
QualcommSa8650p Firmware Version-
   QualcommSa8650p
QualcommSa8770p Firmware Version-
   QualcommSa8770p
QualcommSa8775p Firmware Version-
   QualcommSa8775p
QualcommSa9000p Firmware Version-
   QualcommSa9000p
QualcommSrv1h Firmware Version-
   QualcommSrv1h
QualcommSrv1l Firmware Version-
   QualcommSrv1l
QualcommSrv1m Firmware Version-
   QualcommSrv1m
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.247
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.