VulnerabilityAnalyzed
CVE-2024-23374
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
MEDIUM 6.7EPSS 0.11%
Does this matter?
Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.
Description
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.11% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-787
- Affected
- qualcomm/wsa8835 firmware · qualcomm/wsa8830 firmware · qualcomm/wcn3988 firmware · qualcomm/wcn3980 firmware · qualcomm/wcd9380 firmware · qualcomm/sw5100p firmware · qualcomm/sw5100 firmware · qualcomm/snapdragon w5\+ gen 1 wearable platform firmware · qualcomm/snapdragon auto 5g modem-rf gen 2 firmware · qualcomm/snapdragon 8 gen 1 mobile platform firmware · qualcomm/sa8195p firmware · qualcomm/sa8155p firmware · qualcomm/sa8150p firmware · qualcomm/sa8145p firmware · qualcomm/sa6155p firmware · qualcomm/sa6150p firmware · qualcomm/sa6145p firmware · qualcomm/qca9377 firmware · qualcomm/qca9367 firmware · qualcomm/qca6698aq firmware · +6 more
- Source
- product-security@qualcomm.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.