CVE-2024-33058Insufficient Granularity of Access Control in INC Snapdragon

Severity
7.5HIGHNVD
EPSS
0.1%
top 84.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7

Description

Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 0.8 | Impact: 6.0

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon184 versions+183

🔴Vulnerability Details

1
GHSA
GHSA-vfh3-25rf-469v: Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP2025-04-07

📋Vendor Advisories

1
Android
CVE-2024-33058: Closed-source component2025-04-01