Cyber Posture

CVE-2024-33041

Medium

Published: 06 January 2025

Published
06 January 2025
Modified
11 August 2025
KEV Added
Patch
CVSS Score 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0005 14.8th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Description

Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,

Security Summary

CVE-2024-33041 is a memory corruption vulnerability arising from missing input parameter validation for the number of fences in fence frame IOCTL calls. It affects Qualcomm components and is linked to CWE-823 (Access of Uninitialized Pointer) and CWE-787 (Out-of-bounds Write). The vulnerability received a CVSS v3.1 base score of 6.7 (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) and was published on 2025-01-06.

The attack requires local access with high privileges, low complexity, and no user interaction. An attacker meeting these conditions can achieve high impacts on confidentiality, integrity, and availability, potentially leading to arbitrary code execution or system compromise through memory corruption.

The Qualcomm January 2025 Security Bulletin provides details on affected products and mitigation, available at https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html.

Details

CWE(s)
CWE-823CWE-787

Affected Products

qualcomm
fastconnect 6900 firmware
all versions
qualcomm
fastconnect 7800 firmware
all versions
qualcomm
qam8295p firmware
all versions
qualcomm
qca6574au firmware
all versions
qualcomm
qca6696 firmware
all versions
qualcomm
qcm8550 firmware
all versions
qualcomm
qcs6490 firmware
all versions
qualcomm
qcs8550 firmware
all versions
qualcomm
video collaboration vc3 platform firmware
all versions
qualcomm
sa6145p firmware
all versions
+25 more product configuration(s) — see NVD for full list

References