CVE-2024-23350Reachable Assertion in INC Snapdragon

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 72.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5

Description

Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon25 versions+24

🔴Vulnerability Details

1
GHSA
GHSA-jfgv-r9x2-7mhr: Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the2024-08-05

📋Vendor Advisories

1
Android
CVE-2024-23350: Closed-source component2024-08-01

🕵️Threat Intelligence

1
Bleepingcomputer
Google fixes Android kernel zero-day exploited in targeted attacks2024-08-05