ZeroHour

CVE-2024-38410

CVSS 3.1
7.8 high
EPSS
<1%p1
Published
()
Modified
Description

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

Vendors
qualcomm
Products
wsa8845h firmware, wsa8845 firmware, wsa8840 firmware, wsa8835 firmware, wsa8830 firmware, wcn3660b firmware, wcn3620 firmware, wcd9385 firmware, wcd9380 firmware, wcd9375 firmware, wcd9370 firmware, snapdragon 8cx gen 3 compute platform firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.