PT-2024-25082 · Unknown · Npu Firmware
Published
2024-12-02
·
Updated
2024-12-11
·
CVE-2024-33037
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
NPU firmware (affected versions not specified)
Description
The issue concerns information disclosure due to the NPU firmware sending an invalid IPC message to the NPU driver. This occurs because the driver does not validate the IPC message it receives from the firmware.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Over-read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Npu Firmware