CVE-2024-33039

Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:qam8255p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qam8255p:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:qam8650p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qam8650p:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:qam8775p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qam8775p:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:qamsrv1h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qamsrv1h:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:qamsrv1m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qamsrv1m:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:sa7255p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa7255p:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:sa7775p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa7775p:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:sa8255p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8255p:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:sa8620p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8620p:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:sa8650p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8650p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:sa8770p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8770p:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:qualcomm:sa8775p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8775p:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:qualcomm:sa9000p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa9000p:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:qualcomm:snapdragon_w5\+_gen_1_wearable_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_w5\+_gen_1_wearable_platform:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:qualcomm:srv1h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:srv1h:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:qualcomm:srv1m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:srv1m:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:qualcomm:sw5100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:qualcomm:sw5100p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100p:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3988:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*

History

11 Dec 2024, 16:15

Type Values Removed Values Added
Summary
  • (es) Corrupción de memoria cuando el cliente PAL llama a las API del servicio PAL pasando un valor aleatorio como identificador y el servicio no valida el identificador.
References () https://docs.qualcomm.com/product/publicresources/securitybulletin/december-2024-bulletin.html - () https://docs.qualcomm.com/product/publicresources/securitybulletin/december-2024-bulletin.html - Patch, Vendor Advisory
CPE cpe:2.3:h:qualcomm:srv1m:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_w5\+_gen_1_wearable_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw5100p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8775p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8650p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qamsrv1m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qam8255p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3988:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8620p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:srv1h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qam8775p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8650p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:srv1m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qamsrv1h:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8775p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qam8650p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8255p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qamsrv1h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa7775p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8255p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qam8775p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa9000p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qam8650p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qam8255p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sw5100:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa7255p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8770p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa7775p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa7255p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8620p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:srv1h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa9000p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_w5\+_gen_1_wearable_platform:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw5100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qamsrv1m:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8770p_firmware:-:*:*:*:*:*:*:*
First Time Qualcomm qamsrv1h
Qualcomm snapdragon W5\+ Gen 1 Wearable Platform Firmware
Qualcomm srv1m Firmware
Qualcomm qam8650p Firmware
Qualcomm wsa8835
Qualcomm wsa8830
Qualcomm
Qualcomm srv1h Firmware
Qualcomm wcn3988
Qualcomm qamsrv1h Firmware
Qualcomm wcn3980
Qualcomm sa7775p
Qualcomm qamsrv1m
Qualcomm snapdragon W5\+ Gen 1 Wearable Platform
Qualcomm qam8255p
Qualcomm sa8620p
Qualcomm sa8255p Firmware
Qualcomm qam8255p Firmware
Qualcomm sa7255p
Qualcomm sa8770p Firmware
Qualcomm sa7255p Firmware
Qualcomm srv1m
Qualcomm sa8255p
Qualcomm sa8620p Firmware
Qualcomm sw5100p
Qualcomm wsa8835 Firmware
Qualcomm wcn3988 Firmware
Qualcomm sw5100
Qualcomm sw5100p Firmware
Qualcomm qam8775p
Qualcomm sa8775p Firmware
Qualcomm sa9000p Firmware
Qualcomm qam8775p Firmware
Qualcomm sa9000p
Qualcomm qamsrv1m Firmware
Qualcomm wsa8830 Firmware
Qualcomm sa7775p Firmware
Qualcomm sa8650p Firmware
Qualcomm sa8775p
Qualcomm wcn3980 Firmware
Qualcomm qam8650p
Qualcomm sw5100 Firmware
Qualcomm sa8770p
Qualcomm srv1h
Qualcomm sa8650p

02 Dec 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-02 11:15

Updated : 2024-12-11 16:15


NVD link : CVE-2024-33039

Mitre link : CVE-2024-33039

CVE.ORG link : CVE-2024-33039


JSON object : View

Products Affected

qualcomm

  • sa8620p_firmware
  • qam8650p
  • wcn3980
  • sa9000p_firmware
  • snapdragon_w5\+_gen_1_wearable_platform
  • sa8775p
  • sa7775p_firmware
  • qam8775p_firmware
  • qam8255p
  • qamsrv1m_firmware
  • sw5100
  • wcn3988
  • wsa8830_firmware
  • sa7255p_firmware
  • srv1h
  • qamsrv1h_firmware
  • wsa8835_firmware
  • sa7775p
  • srv1m_firmware
  • sa8620p
  • sa8650p_firmware
  • wsa8835
  • sw5100_firmware
  • qam8650p_firmware
  • wcn3988_firmware
  • sa8775p_firmware
  • sa8255p
  • qamsrv1h
  • snapdragon_w5\+_gen_1_wearable_platform_firmware
  • srv1h_firmware
  • srv1m
  • sw5100p_firmware
  • wsa8830
  • qam8775p
  • sa7255p
  • qam8255p_firmware
  • sa8770p_firmware
  • sw5100p
  • sa8255p_firmware
  • sa8650p
  • sa9000p
  • sa8770p
  • qamsrv1m
  • wcn3980_firmware
CWE
CWE-822

Untrusted Pointer Dereference