CVE-2024-49840

Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:qcc2073_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcc2073:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:qcc2076_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcc2076:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*

History

05 Feb 2025, 16:02

Type Values Removed Values Added
First Time Qualcomm fastconnect 6900 Firmware
Qualcomm wsa8840 Firmware
Qualcomm fastconnect 6900
Qualcomm wsa8845h Firmware
Qualcomm sc8380xp
Qualcomm qcc2073 Firmware
Qualcomm fastconnect 7800 Firmware
Qualcomm wcd9385 Firmware
Qualcomm wsa8845h
Qualcomm sc8380xp Firmware
Qualcomm qcc2073
Qualcomm qcc2076
Qualcomm wsa8840
Qualcomm fastconnect 7800
Qualcomm wcd9385
Qualcomm
Qualcomm wsa8845 Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm qcc2076 Firmware
Qualcomm wsa8845
References () https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html - () https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html - Vendor Advisory
CWE CWE-119
Summary
  • (es) Corrupción de memoria al invocar llamadas IOCTL desde el espacio del usuario para validar la funcionalidad de cifrado o descifrado FIPS.
CPE cpe:2.3:h:qualcomm:qcc2073:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcc2076_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcc2076:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcc2073_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*

03 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 17:15

Updated : 2025-02-05 16:02


NVD link : CVE-2024-49840

Mitre link : CVE-2024-49840

CVE.ORG link : CVE-2024-49840


JSON object : View

Products Affected

qualcomm

  • wsa8845h_firmware
  • wsa8845
  • wcd9385
  • wsa8840_firmware
  • fastconnect_7800_firmware
  • wsa8845h
  • sc8380xp
  • fastconnect_6900_firmware
  • qcc2076
  • wcd9380_firmware
  • wcd9385_firmware
  • wcd9380
  • fastconnect_6900
  • qcc2073
  • qcc2076_firmware
  • wsa8845_firmware
  • wsa8840
  • sc8380xp_firmware
  • qcc2073_firmware
  • fastconnect_7800
CWE
CWE-823

Use of Out-of-range Pointer Offset

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer