CVE-2024-43061

HIGH

Qualcomm FastConnect and Snapdragon Firmware - Use-After-Free in Voice Activation Sound Model Handling

Title source: llm
STIX 2.1

Description

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (30)
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/qam8295p_firmware
qualcomm/qca6574au_firmware
qualcomm/qca6696_firmware
qualcomm/qca9367_firmware
qualcomm/qca9377_firmware
qualcomm/qcs8550_firmware
qualcomm/sa6145p_firmware
qualcomm/sa6150p_firmware
... and 20 more
Published Mar 03, 2025
Tracked Since Feb 18, 2026