CVE-2024-23360

Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6700:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_7c\+_gen_3_compute_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_7c\+_gen_3_compute:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:sc8280xp-abbb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8280xp-abbb:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*

History

09 Jan 2025, 21:26

Type Values Removed Values Added
CPE cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_7c\+_gen_3_compute:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8280xp-abbb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6700:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_7c\+_gen_3_compute_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8280xp-abbb:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
References () https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2024-bulletin.html - () https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2024-bulletin.html - Vendor Advisory
First Time Qualcomm snapdragon 7c\+ Gen 3 Compute
Qualcomm wcd9380
Qualcomm wsa8835 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 6900
Qualcomm sc8280xp-abbb
Qualcomm sc8280xp-abbb Firmware
Qualcomm wsa8845h Firmware
Qualcomm wsa8845h
Qualcomm wsa8835
Qualcomm wsa8845 Firmware
Qualcomm fastconnect 6700 Firmware
Qualcomm wcd9385 Firmware
Qualcomm fastconnect 6900 Firmware
Qualcomm snapdragon 7c\+ Gen 3 Compute Firmware
Qualcomm wsa8845
Qualcomm wsa8830 Firmware
Qualcomm sc8380xp
Qualcomm wsa8830
Qualcomm wsa8840
Qualcomm sc8380xp Firmware
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm fastconnect 7800 Firmware
Qualcomm wsa8840 Firmware
Qualcomm
Qualcomm fastconnect 6700
CWE NVD-CWE-Other

21 Nov 2024, 08:57

Type Values Removed Values Added
Summary
  • (es) Corrupción de la memoria al crear un cliente LPAC, ya que al motor LPAC se le permitió acceder a los registros de GPU.
References () https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2024-bulletin.html - () https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2024-bulletin.html -

03 Jun 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-03 10:15

Updated : 2025-01-09 21:26


NVD link : CVE-2024-23360

Mitre link : CVE-2024-23360

CVE.ORG link : CVE-2024-23360


JSON object : View

Products Affected

qualcomm

  • wsa8840_firmware
  • sc8380xp_firmware
  • wsa8840
  • fastconnect_6700_firmware
  • wsa8845
  • sc8380xp
  • wsa8845h_firmware
  • fastconnect_7800
  • sc8280xp-abbb_firmware
  • wsa8830
  • wcd9380
  • wsa8830_firmware
  • wcd9385
  • wsa8835
  • wsa8845_firmware
  • wcd9385_firmware
  • fastconnect_7800_firmware
  • snapdragon_7c\+_gen_3_compute_firmware
  • snapdragon_7c\+_gen_3_compute
  • fastconnect_6700
  • wsa8845h
  • fastconnect_6900_firmware
  • sc8280xp-abbb
  • fastconnect_6900
  • wcd9380_firmware
  • wsa8835_firmware
CWE
CWE-284

Improper Access Control

NVD-CWE-Other