Executive brief
A use-after-free vulnerability exists in multiple Qualcomm chipsets due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. This flaw allows for local exploitation and has been observed being exploited in the wild.
Affected products
- Qualcomm FastConnect 6700 -
- Qualcomm FastConnect 6800 -
- Qualcomm FastConnect 6900 -
- Qualcomm FastConnect 7800 -
- Qualcomm QAM8295P -
- Qualcomm QCA6174A -
- Qualcomm QCA6391 -
- Qualcomm QCA6426 -
- Qualcomm QCA6436 -
- Qualcomm QCA6574AU -
- Qualcomm QCA6584AU -
- Qualcomm QCA6595 -
- Qualcomm QCA6595AU -
- Qualcomm QCA6688AQ -
- Qualcomm QCA6696 -
- Qualcomm QCA6698AQ -
- Qualcomm QCS410 -
- Qualcomm QCS610 -
- Qualcomm QCS6490 -
- Qualcomm SA4150P -
- Qualcomm SA4155P -
- Qualcomm SA6145P -
Timeline
- 2024-10-08: disclosed
- 2024-10-08: kev added: Added to CISA KEV catalog
- 2024-10-08: patched: Qualcomm released a security bulletin with patches.
- 2024-10-08: exploited: Reported as exploited in the wild at time of publication.