CVE-2024-23377

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:wsa8832_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8832:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:wcn7880_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn7880:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:wcn6755_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn6755:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:wcn6650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn6650:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:wcd9395_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9395:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:wcd9390_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9390:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:qualcomm:wcd9378_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:qualcomm:wcd9375_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9375:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:qualcomm:wcd9371_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9371:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9370:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:qualcomm:sxr2250p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2250p:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:qualcomm:sxr2230p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2230p:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:qualcomm:sxr1230p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr1230p:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:qualcomm:ssg2125p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ssg2125p:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:qualcomm:ssg2115p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ssg2115p:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_ar2_gen_1_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_ar2_gen_1_platform:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_8\+_gen_2_mobile_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_8\+_gen_2_mobile_platform:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_8_gen_2_mobile_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_8_gen_2_mobile_platform:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:qualcomm:sm8550p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm8550p:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:qualcomm:sm7550_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm7550:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:qualcomm:sm7525_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm7525:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:qualcomm:sg8275p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sg8275p:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:qualcomm:sg8275_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sg8275:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:qualcomm:sd_8_gen1_5g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_8_gen1_5g:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:qualcomm:video_collaboration_vc5_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:video_collaboration_vc5_platform:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:qualcomm:qcs8550_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs8550:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:qualcomm:qcs8250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs8250:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:qualcomm:qcs7230_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs7230:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:qualcomm:qcm8550_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcm8550:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6391:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*

History

07 Nov 2024, 19:59

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:h:qualcomm:wcd9375:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_8_gen1_5g:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn6755:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm7525:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sg8275p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr2230p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sm7550_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sg8275p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs8250:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9371:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8832_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd_8_gen1_5g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm7550:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcs8550_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6391:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8832:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9371_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcm8550_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9370:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sg8275:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9390_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn6755_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_ar2_gen_1_platform:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn7880_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcs7230_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcs8250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9395_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ssg2125p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs7230:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr2250p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9395:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:ssg2125p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9375_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn6650:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:video_collaboration_vc5_platform:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_8_gen_2_mobile_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2250p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_8\+_gen_2_mobile_platform:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcm8550:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sm8550p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9390:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ssg2115p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_ar2_gen_1_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2230p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:video_collaboration_vc5_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs8550:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sg8275_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm8550p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_8_gen_2_mobile_platform:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr1230p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:ssg2115p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn6650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr1230p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_8\+_gen_2_mobile_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn7880:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sm7525_firmware:-:*:*:*:*:*:*:*
First Time Qualcomm wsa8832 Firmware
Qualcomm wsa8845h Firmware
Qualcomm wcd9375 Firmware
Qualcomm wsa8835
Qualcomm wcn7880
Qualcomm qcm8550 Firmware
Qualcomm snapdragon 8\+ Gen 2 Mobile Platform Firmware
Qualcomm wcd9385 Firmware
Qualcomm wcd9375
Qualcomm wcd9385
Qualcomm wcn6755
Qualcomm fastconnect 6900
Qualcomm wcd9370 Firmware
Qualcomm video Collaboration Vc5 Platform Firmware
Qualcomm wcd9371 Firmware
Qualcomm wsa8835 Firmware
Qualcomm wcd9395
Qualcomm qcs8550
Qualcomm wcd9395 Firmware
Qualcomm wsa8845h
Qualcomm snapdragon 8\+ Gen 2 Mobile Platform
Qualcomm wcn6650 Firmware
Qualcomm sg8275
Qualcomm snapdragon 8 Gen 2 Mobile Platform
Qualcomm sxr2230p
Qualcomm fastconnect 7800
Qualcomm sm8550p
Qualcomm qca6391
Qualcomm sg8275 Firmware
Qualcomm qca6391 Firmware
Qualcomm video Collaboration Vc5 Platform
Qualcomm sd 8 Gen1 5g Firmware
Qualcomm snapdragon Ar2 Gen 1 Platform Firmware
Qualcomm ssg2125p
Qualcomm wsa8840
Qualcomm qcs8250 Firmware
Qualcomm wcd9380 Firmware
Qualcomm sm7525 Firmware
Qualcomm wcn6755 Firmware
Qualcomm fastconnect 6900 Firmware
Qualcomm wcd9371
Qualcomm wsa8845
Qualcomm sm7550
Qualcomm sxr1230p Firmware
Qualcomm wsa8840 Firmware
Qualcomm
Qualcomm ssg2115p Firmware
Qualcomm wsa8832
Qualcomm sxr2250p
Qualcomm sm7550 Firmware
Qualcomm qcs8550 Firmware
Qualcomm wcd9378 Firmware
Qualcomm ssg2125p Firmware
Qualcomm qcs7230 Firmware
Qualcomm snapdragon Ar2 Gen 1 Platform
Qualcomm wcd9378
Qualcomm qcs8250
Qualcomm sd 8 Gen1 5g
Qualcomm ssg2115p
Qualcomm sxr2250p Firmware
Qualcomm sm7525
Qualcomm fastconnect 7800 Firmware
Qualcomm sxr2230p Firmware
Qualcomm wcd9390
Qualcomm sxr1230p
Qualcomm snapdragon 8 Gen 2 Mobile Platform Firmware
Qualcomm sg8275p Firmware
Qualcomm wcd9370
Qualcomm wsa8845 Firmware
Qualcomm sg8275p
Qualcomm wcd9380
Qualcomm wcd9390 Firmware
Qualcomm sm8550p Firmware
Qualcomm qcs7230
Qualcomm wsa8830
Qualcomm wcn6650
Qualcomm qcm8550
Qualcomm wsa8830 Firmware
Qualcomm wcn7880 Firmware
Summary
  • (es) Corrupción de memoria al invocar el comando IOCTL desde el espacio de usuario, cuando un usuario modifica el tamaño del paquete original del comando después de que las propiedades del sistema ya se hayan enviado al controlador EVA.
References () https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html - () https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html - Patch, Vendor Advisory

04 Nov 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-04 10:15

Updated : 2024-11-07 19:59


NVD link : CVE-2024-23377

Mitre link : CVE-2024-23377

CVE.ORG link : CVE-2024-23377


JSON object : View

Products Affected

qualcomm

  • wcn7880_firmware
  • sm7525_firmware
  • wsa8845h_firmware
  • qcs7230_firmware
  • wsa8832_firmware
  • wcd9395
  • ssg2125p_firmware
  • video_collaboration_vc5_platform_firmware
  • wcd9378
  • wcd9380_firmware
  • wcn6650
  • qca6391_firmware
  • qcs8250
  • wcn6755_firmware
  • sxr1230p_firmware
  • wcd9390_firmware
  • wsa8845_firmware
  • qcs8550
  • sd_8_gen1_5g_firmware
  • wsa8835
  • ssg2125p
  • sxr2230p_firmware
  • sm7550_firmware
  • sxr2230p
  • sg8275p
  • sd_8_gen1_5g
  • wsa8830_firmware
  • wcd9370_firmware
  • video_collaboration_vc5_platform
  • qcm8550_firmware
  • snapdragon_ar2_gen_1_platform
  • snapdragon_8\+_gen_2_mobile_platform_firmware
  • wcd9395_firmware
  • qcs8550_firmware
  • sm7525
  • qcs7230
  • wsa8840_firmware
  • qcm8550
  • sm8550p
  • wcd9375
  • wsa8830
  • snapdragon_8\+_gen_2_mobile_platform
  • sg8275
  • wsa8840
  • wcd9378_firmware
  • sxr1230p
  • snapdragon_ar2_gen_1_platform_firmware
  • snapdragon_8_gen_2_mobile_platform_firmware
  • wsa8845h
  • sg8275_firmware
  • ssg2115p
  • wsa8832
  • sm8550p_firmware
  • wcn6650_firmware
  • ssg2115p_firmware
  • wcd9385
  • wsa8845
  • fastconnect_7800
  • wcd9390
  • qcs8250_firmware
  • wcd9375_firmware
  • fastconnect_6900
  • sxr2250p_firmware
  • wsa8835_firmware
  • wcn7880
  • fastconnect_6900_firmware
  • fastconnect_7800_firmware
  • wcd9371
  • wcn6755
  • sxr2250p
  • wcd9370
  • qca6391
  • wcd9380
  • sm7550
  • wcd9371_firmware
  • wcd9385_firmware
  • sg8275p_firmware
  • snapdragon_8_gen_2_mobile_platform
CWE
NVD-CWE-Other CWE-823

Use of Out-of-range Pointer Offset