CVSS v3.1 Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 82.2% of known CVEs.
Oct 08, 2024
Oct 29, 2024
Threat Analysis
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.
Remediation Directive
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
External Intelligence
https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/dsp-kernel/-/commit/0e27b6c7d2bd8d0453e4465ac2ca49a8f8c440e2
https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/dsp-kernel/-/commit/0e27b6c7d2bd8d0453e4465ac2ca49a8f8c440e2
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2024-43047