PT-2025-2313 · Qualcomm · Snapdragon+16
Published
2025-01-06
·
Updated
2025-01-10
·
CVE-2024-23366
CVSS v3.1
6.6
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Mailbox software (affected versions not specified)
Description:
The issue occurs when a message received from a user is larger than the mailbox size, causing an information disclosure while invoking the mailbox write API. This happens through the
mailbox write API endpoint when a user sends a message that exceeds the mailbox size limit. The message size variable is involved in this issue. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Over-read
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snapdragon
Qam8255P Firmware
Qam8295P Firmware
Qam8650P Firmware
Qam8775P Firmware
Qamsrv1H Firmware
Qca6595Au Firmware
Qca6696 Firmware
Qca6698Aq Firmware
Sa8255P Firmware
Sa8295P Firmware
Sa8540P Firmware
Sa8650P Firmware
Sa8770P Firmware
Sa8775P Firmware
Sa9000P Firmware
Srv1H Firmware