PT-2023-9585 · Qualcomm · Qualcomm Snapdragon Auto

CVE-2024-23376

·

Publicado

2023-11-28

·

Atualizado

2024-10-16

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto versions prior to WSA8835
Description The issue is related to memory corruption that occurs when sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call. This can potentially allow an attacker to execute arbitrary code. The vulnerability is also described as a use-after-free issue in the Qualcomm Snapdragon Auto software.
Recommendations For Qualcomm Snapdragon Auto versions prior to WSA8835, patch the affected systems immediately to resolve the issue. As a temporary workaround, consider restricting access to the IOCTL call to minimize the risk of exploitation.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-08506
CVE-2024-23376

Produtos afetados

Qualcomm Snapdragon Auto