CVE-2024-43047
Use After Free in DSP Service
Qualcomm Multiple Chipsets Use-After-Free Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CISA notes
https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/dsp-kernel/-/commit/0e27b6c7d2bd8d0453e4465ac2ca49a8f8c440e2 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43047
Description
Memory corruption while maintaining memory maps of HLOS memory.
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Qualcomm, Inc. | Snapdragon | FastConnect 6700 FastConnect 6800 FastConnect 6900 FastConnect 7800 QAM8295P QCA6174A QCA6391 QCA6426 QCA6436 QCA6574AU QCA6584AU QCA6595 QCA6595AU QCA6688AQ QCA6696 QCA6698AQ QCS410 QCS610 QCS6490 Qualcomm Video Collaboration VC1 Platform Qualcomm Video Collaboration VC3 Platform SA4150P SA4155P SA6145P SA6150P SA6155P SA8145P SA8150P SA8155P SA8195P SA8295P SD660 SD865 5G SG4150P Snapdragon 660 Mobile Platform Snapdragon 680 4G Mobile Platform Snapdragon 685 4G Mobile Platform (SM6225-AD) Snapdragon 8 Gen 1 Mobile Platform Snapdragon 865 5G Mobile Platform Snapdragon 865+ 5G Mobile Platform (SM8250-AB) Snapdragon 870 5G Mobile Platform (SM8250-AC) Snapdragon 888 5G Mobile Platform Snapdragon 888+ 5G Mobile Platform (SM8350-AC) Snapdragon Auto 5G Modem-RF Snapdragon Auto 5G Modem-RF Gen 2 Snapdragon X55 5G Modem-RF System Snapdragon XR2 5G Platform SW5100 SW5100P SXR2130 WCD9335 WCD9341 WCD9370 WCD9375 WCD9380 WCD9385 WCN3950 WCN3980 WCN3988 WCN3990 WSA8810 WSA8815 WSA8830 WSA8835 |
References
1 LinksRecord Details
More from Qualcomm, Inc.
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.