Memory corruption while redirecting log file to any file location with any file name.
The error results from improper input data validation (CWE-20) during the operation of redirecting an event log file to any location and under any file name. Insufficient control of passed parameters leads to memory corruption. The attack can be performed remotely, without authentication and without user interaction.
An attacker can gain full control over the vulnerable component, including confidentiality, integrity, and system availability – which corresponds to the ability to execute arbitrary code (RCE) or cause serious device stability violations.
Apply patches available from the vendor according to the references – detailed information about fixes is contained in Qualcomm's October 2024 security bulletin: https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html
Qualcomm Snapdragon X65 5G Modem-RF System (firmware), Qualcomm SDX65M (firmware), Qualcomm SDX55 (firmware) – exact versions indicated in vendor references (Qualcomm October 2024 bulletin)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HQualcomm Ipq8076
HWQualcommall versionsQualcomm Ipq8076a
HWQualcommall versionsQualcomm Ipq8076a Firmware
OSQualcommall versionsQualcomm Ipq8076 Firmware
OSQualcommall versionsQualcomm Ipq8078
HWQualcommall versionsQualcomm Ipq8078a
HWQualcommall versionsQualcomm Ipq8078a Firmware
OSQualcommall versionsQualcomm Ipq8078 Firmware
OSQualcommall versionsQualcomm Ipq8173
HWQualcommall versionsQualcomm Ipq8173 Firmware
OSQualcommall versionsQualcomm Ipq8174
HWQualcommall versionsQualcomm Ipq8174 Firmware
OSQualcommall versionsQualcomm Ipq9008
HWQualcommall versionsQualcomm Ipq9008 Firmware
OSQualcommall versionsQualcomm Ipq9554
HWQualcommall versionsQualcomm Ipq9554 Firmware
OSQualcommall versionsQualcomm Ipq9574
HWQualcommall versionsQualcomm Ipq9574 Firmware
OSQualcommall versionsQualcomm Qca4024
HWQualcommall versionsQualcomm Qca4024 Firmware
OSQualcommall versionsQualcomm Qca8075
HWQualcommall versionsQualcomm Qca8075 Firmware
OSQualcommall versionsQualcomm Qca8081
HWQualcommall versionsQualcomm Qca8081 Firmware
OSQualcommall versionsQualcomm Qca8082
HWQualcommall versionsQualcomm Qca8082 Firmware
OSQualcommall versionsQualcomm Qca8084
HWQualcommall versionsQualcomm Qca8084 Firmware
OSQualcommall versionsQualcomm Qca8085
HWQualcommall versionsQualcomm Qca8085 Firmware
OSQualcommall versions
Related vulnerabilities
Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm
Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR
Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania
Qualcomm: Uszkodzenie pamięci przy parsowaniu ML IE w firmware
Uszkodzenie pamięci w TZ Secure OS podczas inicjalizacji Tunnel Invoke Manager (Qualcomm)