Memory Corruption Vulnerability in Qualcomm Products
CVE-2024-38412

7.8HIGH

Key Information:

Vendor
Qualcomm
Vendor
CVE Published:
3 February 2025

Summary

This vulnerability allows for memory corruption during IOCTL calls, which are intended to handle session errors between user-space applications and the kernel. If exploited, this issue could lead to unauthorized access or modifications within the kernel space, potentially compromising system stability and integrity. Users and organizations relying on Qualcomm products should apply relevant patches and updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Snapdragon Snapdragon Auto FastConnect 7800

Snapdragon Snapdragon Auto Snapdragon 8 Gen 3 Mobile Platform

Snapdragon Snapdragon Auto WCD9390

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.