SB2024120362 - Multiple vulnerabilities in Qualcomm chipsets



SB2024120362 - Multiple vulnerabilities in Qualcomm chipsets

Published: December 3, 2024

Security Bulletin ID SB2024120362
Severity
Medium
Patch available
YES
Number of vulnerabilities 13
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 8% Low 92%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 13 secuirty vulnerabilities.


1) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2024-33036)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Camera Driver. A local privileged application can execute arbitrary code.


2) Use After Free (CVE-ID: CVE-2024-33040)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Camera Driver. A local privileged application can execute arbitrary code.


3) Buffer over-read (CVE-ID: CVE-2024-33037)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in Neural Processing Unit. A local application can read and manipulate data.


4) Untrusted Pointer Dereference (CVE-ID: CVE-2024-33039)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.


5) Use After Free (CVE-ID: CVE-2024-33053)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Video. A local privileged application can execute arbitrary code.


6) Improper Validation of Array Index (CVE-ID: CVE-2024-33044)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Hypervisor. A local application can execute arbitrary code.


7) Buffer over-read (CVE-ID: CVE-2024-33056)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in MProc. A local application can execute arbitrary code.


8) Stack-based buffer overflow (CVE-ID: CVE-2024-43048)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Performance. A local application can execute arbitrary code.


9) Memory corruption (CVE-ID: CVE-2024-43049)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


10) Stack-based buffer overflow (CVE-ID: CVE-2024-43050)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


11) Input validation error (CVE-ID: CVE-2024-43052)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Video Analytics and Processing. A local application can execute arbitrary code.


12) Memory corruption (CVE-ID: CVE-2024-43053)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


13) Integer overflow (CVE-ID: CVE-2024-33063)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in WLAN Host Communication. A remote attacker can perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.