CVE-2024-23374

MEDIUM

Qualcomm WSA8835 and related firmware - Stack-based Buffer Overflow via Haptics Debugfs File

Title source: llm
STIX 2.1

Description

Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.

Scores

CVSS v3 6.7
EPSS 0.0006
EPSS Percentile 18.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121 CWE-787
Status published
Products (26)
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/qca6174a_firmware
qualcomm/qca6574au_firmware
qualcomm/qca6584au_firmware
qualcomm/qca6696_firmware
qualcomm/qca6698aq_firmware
qualcomm/qca9367_firmware
qualcomm/qca9377_firmware
qualcomm/sa6145p_firmware
... and 16 more
Published Oct 07, 2024
Tracked Since Feb 18, 2026