SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-33040

Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.

HIGH 7.0EPSS 0.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.

CVSS 3.1
7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.09% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-416
Affected
qualcomm/fastconnect 6800 firmware · qualcomm/fastconnect 6900 firmware · qualcomm/fastconnect 7800 firmware · qualcomm/qam8255p firmware · qualcomm/qca6391 firmware · qualcomm/qca6426 firmware · qualcomm/qca6436 firmware · qualcomm/qca6595au firmware · qualcomm/qca6678aq firmware · qualcomm/sa8255p firmware · qualcomm/sd865 5g firmware · qualcomm/snapdragon 8 gen 1 mobile platform firmware · qualcomm/snapdragon 865 5g mobile platform firmware · qualcomm/snapdragon 865\+ 5g mobile platform firmware · qualcomm/snapdragon 870 5g mobile platform firmware · qualcomm/snapdragon w5\+ gen 1 wearable platform firmware · qualcomm/snapdragon x55 5g modem-rf system firmware · qualcomm/snapdragon xr2 5g platform firmware · qualcomm/sw5100 firmware · qualcomm/sw5100p firmware · +10 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.