CVE-2024-53033

Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:*:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:*:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:*:*:*:*:*:*:*:*

History

07 Mar 2025, 11:47

Type Values Removed Values Added
CWE CWE-119
First Time Qualcomm sc8380xp
Qualcomm wcd9380
Qualcomm fastconnect 6900 Firmware
Qualcomm wsa8845h
Qualcomm sc8380xp Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 7800 Firmware
Qualcomm wsa8840 Firmware
Qualcomm wsa8845h Firmware
Qualcomm fastconnect 7800
Qualcomm wsa8845 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wcd9380 Firmware
Qualcomm wsa8840
Qualcomm
Qualcomm wsa8845
References () https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html - () https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html - Vendor Advisory
Summary
  • (es) Corrupción de memoria al realizar una llamada de Escape cuando el usuario proporciona una dirección de kernel válida en lugar de una dirección de búfer de usuario válida.
CPE cpe:2.3:h:qualcomm:fastconnect_6900:*:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:*:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:*:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:*:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:*:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:*:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:*:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:*:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*

03 Mar 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 11:15

Updated : 2025-03-07 11:47


NVD link : CVE-2024-53033

Mitre link : CVE-2024-53033

CVE.ORG link : CVE-2024-53033


JSON object : View

Products Affected

qualcomm

  • wsa8845_firmware
  • wsa8845h
  • sc8380xp_firmware
  • wsa8840
  • wcd9385
  • fastconnect_7800
  • fastconnect_7800_firmware
  • wcd9380_firmware
  • sc8380xp
  • wcd9380
  • wcd9385_firmware
  • wsa8840_firmware
  • wsa8845
  • fastconnect_6900
  • wsa8845h_firmware
  • fastconnect_6900_firmware
CWE
CWE-822

Untrusted Pointer Dereference

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer