Buffer over-read in Qualcomm products - CVE-2024-38404

 

Buffer over-read in Qualcomm products - CVE-2024-38404

Published: February 3, 2025


Vulnerability identifier: #VU103517
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38404
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in Multi Mode Call Processor. A remote attacker can perform a denial of service (DoS) attack.


Affected software

WCN3660B
Snapdragon X72 5G Modem-RF System
Snapdragon X75 5G Modem-RF System
WCD9340
WCD9370
WCD9375
WCD9390
WCD9395
WCN3610
WCN3620
Snapdragon Wear 4100+ Platform
WCN3680B
WCN3980
WCN6755
WSA8830
WSA8835
WSA8840
WSA8845
WSA8845H
QFW7124
FastConnect 7800
QCA6584AU
QCA6698AQ
QCA8081
QCA8337
QCC710
QCN6224
QCN6274
QFW7114
AR8035
SDX80M
SM7675
SM7675P
SM8635
SM8635P
Snapdragon 429 Mobile Platform
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon Auto 5G Modem-RF Gen 2
Samsung Mobile Firmware
WSA8832
SDM429W
Google Android

How to mitigate CVE-2024-38404

Install security update from vendor's website.

Samsung Mobile Firmware - update to SMR-MAR-2025
Google Android - addressed in versions 12L 2025-02-05, 12 2025-02-05, 13 2025-02-05, 14 2025-02-05, 15 2025-02-05

External References

Related Security Bulletins