Vulnerability Description
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Wsa8845H Firmware | - |
| Qualcomm | Wsa8845H | - |
| Qualcomm | Wsa8845 Firmware | - |
| Qualcomm | Wsa8845 | - |
| Qualcomm | Wsa8840 Firmware | - |
| Qualcomm | Wsa8840 | - |
| Qualcomm | Wsa8835 Firmware | - |
| Qualcomm | Wsa8835 | - |
| Qualcomm | Wsa8830 Firmware | - |
| Qualcomm | Wsa8830 | - |
| Qualcomm | Wcn3660B Firmware | - |
| Qualcomm | Wcn3660B | - |
| Qualcomm | Wcn3620 Firmware | - |
| Qualcomm | Wcn3620 | - |
| Qualcomm | Wcd9385 Firmware | - |
| Qualcomm | Wcd9385 | - |
| Qualcomm | Wcd9380 Firmware | - |
| Qualcomm | Wcd9380 | - |
| Qualcomm | Wcd9375 Firmware | - |
| Qualcomm | Wcd9375 | - |
Related Weaknesses (CWE)
References
- https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024PatchVendor Advisory
FAQ
What is CVE-2024-38410?
CVE-2024-38410 is a vulnerability with a CVSS score of 7.8 (HIGH). Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
How severe is CVE-2024-38410?
CVE-2024-38410 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38410?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Wsa8845H Firmware, Qualcomm Wsa8845H, Qualcomm Wsa8845 Firmware, Qualcomm Wsa8845, Qualcomm Wsa8840 Firmware.