CVE-2024-23377
MEDIUMDescription
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
Is your site exposed to CVE-2024-23377?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qualcomm | wsa8845h_firmware |
| qualcomm | wsa8845h |
| qualcomm | wsa8845_firmware |
| qualcomm | wsa8845 |
| qualcomm | wsa8840_firmware |
| qualcomm | wsa8840 |
| qualcomm | wsa8835_firmware |
| qualcomm | wsa8835 |
| qualcomm | wsa8832_firmware |
| qualcomm | wsa8832 |
| qualcomm | wsa8830_firmware |
| qualcomm | wsa8830 |
| qualcomm | wcn7880_firmware |
| qualcomm | wcn7880 |
| qualcomm | wcn6755_firmware |
| qualcomm | wcn6755 |
| qualcomm | wcn6650_firmware |
| qualcomm | wcn6650 |
| qualcomm | wcd9395_firmware |
| qualcomm | wcd9395 |
| qualcomm | wcd9390_firmware |
| qualcomm | wcd9390 |
| qualcomm | wcd9385_firmware |
| qualcomm | wcd9385 |
| qualcomm | wcd9380_firmware |
| qualcomm | wcd9380 |
| qualcomm | wcd9378_firmware |
| qualcomm | wcd9378 |
| qualcomm | wcd9375_firmware |
| qualcomm | wcd9375 |
| qualcomm | wcd9371_firmware |
| qualcomm | wcd9371 |
| qualcomm | wcd9370_firmware |
| qualcomm | wcd9370 |
| qualcomm | sxr2250p_firmware |
| qualcomm | sxr2250p |
| qualcomm | sxr2230p_firmware |
| qualcomm | sxr2230p |
| qualcomm | sxr1230p_firmware |
| qualcomm | sxr1230p |
| qualcomm | ssg2125p_firmware |
| qualcomm | ssg2125p |
| qualcomm | ssg2115p_firmware |
| qualcomm | ssg2115p |
| qualcomm | snapdragon_ar2_gen_1_platform_firmware |
| qualcomm | snapdragon_ar2_gen_1_platform |
| qualcomm | snapdragon_8\+_gen_2_mobile_platform_firmware |
| qualcomm | snapdragon_8\+_gen_2_mobile_platform |
| qualcomm | snapdragon_8_gen_2_mobile_platform_firmware |
| qualcomm | snapdragon_8_gen_2_mobile_platform |
| qualcomm | sm8550p_firmware |
| qualcomm | sm8550p |
| qualcomm | sm7550_firmware |
| qualcomm | sm7550 |
| qualcomm | sm7525_firmware |
| qualcomm | sm7525 |
| qualcomm | sg8275p_firmware |
| qualcomm | sg8275p |
| qualcomm | sg8275_firmware |
| qualcomm | sg8275 |
| qualcomm | sd_8_gen1_5g_firmware |
| qualcomm | sd_8_gen1_5g |
| qualcomm | video_collaboration_vc5_platform_firmware |
| qualcomm | video_collaboration_vc5_platform |
| qualcomm | qcs8550_firmware |
| qualcomm | qcs8550 |
| qualcomm | qcs8250_firmware |
| qualcomm | qcs8250 |
| qualcomm | qcs7230_firmware |
| qualcomm | qcs7230 |
| qualcomm | qcm8550_firmware |
| qualcomm | qcm8550 |
| qualcomm | qca6391_firmware |
| qualcomm | qca6391 |
| qualcomm | fastconnect_7800_firmware |
| qualcomm | fastconnect_7800 |
| qualcomm | fastconnect_6900_firmware |
| qualcomm | fastconnect_6900 |
References
Frequently Asked Questions
What is CVE-2024-23377? +
How severe is CVE-2024-23377? +
What products are affected by CVE-2024-23377? +
How do I check if I'm vulnerable to CVE-2024-23377? +
Related Vulnerabilities
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it …
A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh …
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware …
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
Memory corruption while performing SCM call.
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount …