PT-2023-9585 · Qualcomm · Qualcomm Snapdragon Auto

Published

2023-11-28

·

Updated

2024-10-16

·

CVE-2024-23376

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto versions prior to WSA8835
Description The issue is related to memory corruption that occurs when sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call. This can potentially allow an attacker to execute arbitrary code. The vulnerability is also described as a use-after-free issue in the Qualcomm Snapdragon Auto software.
Recommendations For Qualcomm Snapdragon Auto versions prior to WSA8835, patch the affected systems immediately to resolve the issue. As a temporary workaround, consider restricting access to the IOCTL call to minimize the risk of exploitation.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-08506
CVE-2024-23376

Affected Products

Qualcomm Snapdragon Auto