Vulnerability Description
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Wsa8835 Firmware | - |
| Qualcomm | Wsa8835 | - |
| Qualcomm | Wsa8830 Firmware | - |
| Qualcomm | Wsa8830 | - |
| Qualcomm | Wcn3988 Firmware | - |
| Qualcomm | Wcn3988 | - |
| Qualcomm | Wcn3980 Firmware | - |
| Qualcomm | Wcn3980 | - |
| Qualcomm | Sw5100P Firmware | - |
| Qualcomm | Sw5100P | - |
| Qualcomm | Sw5100 Firmware | - |
| Qualcomm | Sw5100 | - |
| Qualcomm | Snapdragon Auto 5G Modem-Rf Gen 2 Firmware | - |
| Qualcomm | Snapdragon Auto 5G Modem-Rf Gen 2 | - |
| Qualcomm | Qca9377 Firmware | - |
| Qualcomm | Qca9377 | - |
| Qualcomm | Qca9367 Firmware | - |
| Qualcomm | Qca9367 | - |
| Qualcomm | Qca6698Aq Firmware | - |
| Qualcomm | Qca6698Aq | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-23370?
CVE-2024-23370 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
How severe is CVE-2024-23370?
CVE-2024-23370 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23370?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Wsa8835 Firmware, Qualcomm Wsa8835, Qualcomm Wsa8830 Firmware, Qualcomm Wsa8830, Qualcomm Wcn3988 Firmware.