We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-45560

Time-of-check Time-of-use (TOCTOU) Race Condition in Camera



Description

Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.

Reserved 2024-09-02 | Published 2025-02-03 | Updated 2025-02-03 | Assigner qualcomm


HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

Product status

Default status
unaffected

AQT1000
affected

FastConnect 6200
affected

FastConnect 6700
affected

FastConnect 6800
affected

FastConnect 6900
affected

FastConnect 7800
affected

QCA6391
affected

QCA6420
affected

QCA6430
affected

QCM5430
affected

QCM6490
affected

QCS5430
affected

QCS6490
affected

Qualcomm Video Collaboration VC3 Platform
affected

SC8380XP
affected

SDM429W
affected

Snapdragon 429 Mobile Platform
affected

Snapdragon 7c+ Gen 3 Compute
affected

Snapdragon 8c Compute Platform (SC8180X-AD) "Poipu Lite"
affected

Snapdragon 8cx Compute Platform (SC8180X-AA, AB)
affected

Snapdragon 8cx Gen 2 5G Compute Platform (SC8180X-AC, AF) "Poipu Pro"
affected

Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)
affected

WCD9340
affected

WCD9341
affected

WCD9370
affected

WCD9375
affected

WCD9380
affected

WCD9385
affected

WCN3620
affected

WCN3660B
affected

WSA8810
affected

WSA8815
affected

WSA8830
affected

WSA8835
affected

WSA8840
affected

WSA8845
affected

WSA8845H
affected

References

docs.qualcomm.com/...itybulletin/february-2025-bulletin.html

cve.org (CVE-2024-45560)

nvd.nist.gov (CVE-2024-45560)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-45560

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.