CVE-2024-23386
Published Nov 4, 2024memory corruption when WiFi display APIs are invoked with large random inputs.
Vendor/product archive
129 CVEs tagged to qualcomm / wcd9380_firmware — 3 Critical, 91 High, 35 Medium, 0 Low, 0 Unrated.
memory corruption when WiFi display APIs are invoked with large random inputs.
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the…
Information disclosure while sending implicit broadcast containing APP launch information.
Memory corruption while processing user packets to generate page faults.
Transient DOS while parsing probe response and assoc response frame.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
Memory corruption when keymaster operation imports a shared key.
Information disclosure while handling beacon probe frame during scan entry generation in client side.
Information disclosure while handling beacon or probe response frame in STA.
Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
Memory corruption in HLOS while running kernel address sanitizers (syzkaller) on tmecom with DEBUG_FS enabled.
Information Disclosure while processing IOCTL request in FastRPC.
Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
Memory corruption while reading ACPI config through the user mode app.
Memory corruption when malformed message payload is received from firmware.
Transient DOS in Modem while processing RRC reconfiguration message.
Memory corruption due to improper validation of array index in Audio.
An app with non-privileged access can change global system brightness and cause undesired system behavior.