Memory Corruption Vulnerability in Qualcomm Products
CVE-2024-38412
7.8HIGH
Summary
This vulnerability allows for memory corruption during IOCTL calls, which are intended to handle session errors between user-space applications and the kernel. If exploited, this issue could lead to unauthorized access or modifications within the kernel space, potentially compromising system stability and integrity. Users and organizations relying on Qualcomm products should apply relevant patches and updates to mitigate risks associated with this vulnerability.
Affected Version(s)
Snapdragon Snapdragon Auto FastConnect 7800
Snapdragon Snapdragon Auto Snapdragon 8 Gen 3 Mobile Platform
Snapdragon Snapdragon Auto WCD9390
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved