CVE-2024-49843 HIGH

CVE-2024-49843: Improper Validation of Array Index in Graphics_Linux

Vendor Qualcomm, Inc.
Product Snapdragon
Weakness CWE-129
Published February 3, 2025
Last update February 3, 2025

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.

Key dates

02Disclosure timeline

February 3, 2025 CVE published
February 3, 2025 Record updated