Memory corruption in Qualcomm products - CVE-2024-21482

 

Memory corruption in Qualcomm products - CVE-2024-21482

Published: July 1, 2024


Vulnerability identifier: #VU93528
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21482
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in Linux Boot Loader. A local attacker can execute arbitrary code.


Affected software

QCN5052
QCN6112
QCN6024
QCN6023
QCN5164
QCN5154
QCN5152
QCN5124
QCN5122
QCN6122
QCN5024
QCN5022
QCF8001
QCF8000
QCA9889
QCA9888
QCA8386
QCA8085
QCN9024
Snapdragon X65 5G Modem-RF System
SDX65M
QCN9274
QCN9100
QCN9074
QCN9072
QCN9070
QCA8084
QCN9022
QCN9000
QCN6432
QCN6422
QCN6412
QCN6402
IPQ5028
IPQ8070A
IPQ6028
IPQ6018
IPQ6010
IPQ6000
IPQ5332
IPQ5312
IPQ5302
IPQ8071A
IPQ5010
Immersive Home 326 Platform
Immersive Home 3210 Platform
Immersive Home 318 Platform
Immersive Home 316 Platform
Immersive Home 216 Platform
Immersive Home 214 Platform
IPQ8174
QCA8082
QCA8081
QCA8075
QCA4024
IPQ9574
IPQ9570
IPQ9554
IPQ9008
CSR8811
IPQ8173
IPQ8078A
IPQ8078
IPQ8076A
IPQ8076
IPQ8074A
IPQ8072A
SDX55
QCN6132

How to mitigate CVE-2024-21482

Install security update from vendor's website.


External References

Related Security Bulletins