Use After Free in Qualcomm products - CVE-2024-45566
Published: May 6, 2025
Vulnerability identifier: #VU108717
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45566
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Camera Driver. A local application can execute arbitrary code.
Affected software
Snapdragon 865+ 5G Mobile Platform (SM8250-AB)
WSA8835
WSA8830
WSA8815
WSA8810
WCN3660B
WCN3620
WCD9380
Snapdragon XR2 5G Platform
Snapdragon X55 5G Modem-RF System
Snapdragon 870 5G Mobile Platform (SM8250-AC)
FastConnect 6800
Snapdragon 865 5G Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 429 Mobile Platform
SD865 5G
QCA6436
QCA6426
QCA6391
FastConnect 7800
FastConnect 6900
SXR2130
SDM429W
WSA8835
WSA8830
WSA8815
WSA8810
WCN3660B
WCN3620
WCD9380
Snapdragon XR2 5G Platform
Snapdragon X55 5G Modem-RF System
Snapdragon 870 5G Mobile Platform (SM8250-AC)
FastConnect 6800
Snapdragon 865 5G Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 429 Mobile Platform
SD865 5G
QCA6436
QCA6426
QCA6391
FastConnect 7800
FastConnect 6900
SXR2130
SDM429W
How to mitigate CVE-2024-45566
Install security update from vendor's website.