CVE-2024-38411 Details
Description
Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.
A use-after-free vulnerability has been identified in various chipsets by Qualcomm. This vulnerability leads to memory corruption by allowing user-space to kernel-space buffer registration through IOCTL calls. The issue arises from improper management of memory, which could potentially be exploited to cause unintended behavior in the system.
Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm February 2025 Security Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm fastconnect 6900 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 6900 | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 | All versions |
CPE
Remediation
| |
| qualcomm qcm8550 firmware | All versions |
CPE
Remediation
| |
| qualcomm qcm8550 | All versions |
CPE
Remediation
| |
| qualcomm qcs6490 firmware | All versions |
CPE
Remediation
| |
| qualcomm qcs6490 | All versions |
CPE
Remediation
| |
| qualcomm qcs8550 firmware | All versions |
CPE
Remediation
| |
| qualcomm qcs8550 | All versions |
CPE
Remediation
| |
| qualcomm video collaboration vc3 platform firmware | All versions |
CPE
Remediation
| |
| qualcomm video collaboration vc3 platform | All versions |
CPE
Remediation
| |
| qualcomm sg8275p firmware | All versions |
CPE
Remediation
| |
| qualcomm sg8275p | All versions |
CPE
Remediation
| |
| qualcomm sm8550p firmware | All versions |
CPE
Remediation
| |
| qualcomm sm8550p | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 2 mobile firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 2 mobile | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 3 mobile firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 3 mobile | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8+ gen 2 mobile firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8+ gen 2 mobile | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 | All versions |
CPE
Remediation
| |
| qualcomm wcd9390 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9390 | All versions |
CPE
Remediation
| |
| qualcomm wcd9395 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9395 | All versions |
CPE
Remediation
| |
| qualcomm wsa8840 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8840 | All versions |
CPE
Remediation
| |
| qualcomm wsa8845 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8845 | All versions |
CPE
Remediation
| |
| qualcomm wsa8845h firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8845h | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 11, 2025 | CPE Deprecation Remap | [email protected] |
| Aug 7, 2025 | CPE Deprecation Remap | [email protected] |
| Feb 5, 2025 | Initial Analysis | [email protected] |
| Feb 3, 2025 | New CVE Received | [email protected] |