CVE-2024-53018 Details
Description
Memory corruption may occur while processing the OIS packet parser.
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in the camera driver of various chipsets, including several Snapdragon mobile platforms. This vulnerability may lead to memory corruption while processing the optical image stabilization (OIS) packet parser. The issue arises from improper synchronization, allowing certain operations to be executed out of order, potentially causing memory to be accessed or modified incorrectly.
Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm June 2025 Security Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm fastconnect 6900 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 6900 | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 | All versions |
CPE
Remediation
| |
| qualcomm sdm429w firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm429w | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 429 mobile platform firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 429 mobile platform | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 1 mobile platform firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 1 mobile platform | All versions |
CPE
Remediation
| |
| qualcomm snapdragon w5+ gen 1 wearable platform firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon w5+ gen 1 wearable platform | All versions |
CPE
Remediation
| |
| qualcomm sw5100 firmware | All versions |
CPE
Remediation
| |
| qualcomm sw5100 | All versions |
CPE
Remediation
| |
| qualcomm sw5100p firmware | All versions |
CPE
Remediation
| |
| qualcomm sw5100p | All versions |
CPE
Remediation
| |
| qualcomm sxr2230p firmware | All versions |
CPE
Remediation
| |
| qualcomm sxr2230p | All versions |
CPE
Remediation
| |
| qualcomm sxr2250p firmware | All versions |
CPE
Remediation
| |
| qualcomm sxr2250p | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 | All versions |
CPE
Remediation
| |
| qualcomm wcn3620 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcn3620 | All versions |
CPE
Remediation
| |
| qualcomm wcn3660b firmware | All versions |
CPE
Remediation
| |
| qualcomm wcn3660b | All versions |
CPE
Remediation
| |
| qualcomm wcn3980 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcn3980 | All versions |
CPE
Remediation
| |
| qualcomm wcn3988 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcn3988 | All versions |
CPE
Remediation
| |
| qualcomm wsa8830 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8830 | All versions |
CPE
Remediation
| |
| qualcomm wsa8832 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8832 | All versions |
CPE
Remediation
| |
| qualcomm wsa8835 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8835 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | Initial Analysis | [email protected] |
| Jun 3, 2025 | New CVE Received | [email protected] |