ZeroHour

CVE-2024-23377

CVSS 3.1
6.7 medium
EPSS
<1%p1
Published
()
Modified
Description

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.

Vendors
qualcomm
Products
wsa8845h firmware, wsa8845 firmware, wsa8840 firmware, wsa8835 firmware, wsa8832 firmware, wsa8830 firmware, wcn7880 firmware, wcn6755 firmware, wcn6650 firmware, wcd9395 firmware, wcd9390 firmware, wcd9385 firmware
Weakness
CWE-823
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.