Technical Severity
HIGHCVSS v3.1 Metrics
7.8
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitation Likelihood
EPSS Prediction
1.75
%
Predictive Probability
Percentile Rank
82.5
th
Documented as more likely to be exploited than 82.5% of known CVEs.
Detection Date
Oct 08, 2024
Remediation Due
Oct 29, 2024
CISA Catalog Active
Threat Analysis
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.
Remediation Directive
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
External Intelligence
https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/dsp-kernel/-/commit/0e27b6c7d2bd8d0453e4465ac2ca49a8f8c440e2
https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/dsp-kernel/-/commit/0e27b6c7d2bd8d0453e4465ac2ca49a8f8c440e2
NVD
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2024-43047