CVE-2024-45577 Details
Description
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
A vulnerability has been identified in the camera kernel driver of Qualcomm chipsets, allowing memory corruption through improper input validation. This issue arises when IOCTL calls are made from userspace to the camera driver, particularly to dump request information. The vulnerability is present in various chipsets and could potentially be exploited by manipulating the data sent via these IOCTL calls.
Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm May 2025 Security Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2025-bulletin.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm fastconnect 6900 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 6900 | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 | All versions |
CPE
Remediation
| |
| qualcomm sdm429w firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm429w | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 429 mobile firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 429 mobile | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 1 mobile firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 1 mobile | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 | All versions |
CPE
Remediation
| |
| qualcomm wcn3620 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcn3620 | All versions |
CPE
Remediation
| |
| qualcomm wcn3660b firmware | All versions |
CPE
Remediation
| |
| qualcomm wcn3660b | All versions |
CPE
Remediation
| |
| qualcomm wsa8830 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8830 | All versions |
CPE
Remediation
| |
| qualcomm wsa8835 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8835 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 9, 2025 | Initial Analysis | [email protected] |
| May 6, 2025 | New CVE Received | [email protected] |