Vulnerability Description
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Fastconnect 6800 Firmware | - |
| Qualcomm | Fastconnect 6800 | - |
| Qualcomm | Fastconnect 6900 Firmware | - |
| Qualcomm | Fastconnect 6900 | - |
| Qualcomm | Fastconnect 7800 Firmware | - |
| Qualcomm | Fastconnect 7800 | - |
| Qualcomm | Qam8255P Firmware | - |
| Qualcomm | Qam8255P | - |
| Qualcomm | Qca6391 Firmware | - |
| Qualcomm | Qca6391 | - |
| Qualcomm | Qca6426 Firmware | - |
| Qualcomm | Qca6426 | - |
| Qualcomm | Qca6436 Firmware | - |
| Qualcomm | Qca6436 | - |
| Qualcomm | Qca6595Au Firmware | - |
| Qualcomm | Qca6595Au | - |
| Qualcomm | Qca6678Aq Firmware | - |
| Qualcomm | Qca6678Aq | - |
| Qualcomm | Sa8255P Firmware | - |
| Qualcomm | Sa8255P | - |
Related Weaknesses (CWE)
References
- https://docs.qualcomm.com/product/publicresources/securitybulletin/december-2024PatchVendor Advisory
FAQ
What is CVE-2024-33040?
CVE-2024-33040 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
How severe is CVE-2024-33040?
CVE-2024-33040 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-33040?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Fastconnect 6800 Firmware, Qualcomm Fastconnect 6800, Qualcomm Fastconnect 6900 Firmware, Qualcomm Fastconnect 6900, Qualcomm Fastconnect 7800 Firmware.