PT-2024-12413 · Qualcomm · Qualcomm 4 Gen 1 Mobile Platform

Published

2024-01-01

·

Updated

2024-04-12

·

CVE-2023-33110

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm 4 Gen 1 Mobile Platform (affected versions not specified)
Description The issue arises from the session index variable in the PCM host voice audio driver, which is initialized before PCM open, accessed during event callback from ADSP, and reset during PCM close. This may lead to a race condition between event callback and PCM close, causing memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2023-33110

Affected Products

Qualcomm 4 Gen 1 Mobile Platform