CVE-2024-33032
MEDIUMCVSS 6.7/10EPSS 0.10%
Last modified
CVE-2024-33032 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Wsa8835 Firmware | All versions |
| Qualcomm | Wsa8832 Firmware | All versions |
| Qualcomm | Wsa8830 Firmware | All versions |
| Qualcomm | Wsa8815 Firmware | All versions |
| Qualcomm | Wsa8810 Firmware | All versions |
| Qualcomm | Wcn3988 Firmware | All versions |
| Qualcomm | Wcn3980 Firmware | All versions |
| Qualcomm | Wcn3950 Firmware | All versions |
| Qualcomm | Wcn3680b Firmware | All versions |
| Qualcomm | Wcn3660b Firmware | All versions |
| Qualcomm | Wcn3610 Firmware | All versions |
| Qualcomm | Wcd9385 Firmware | All versions |
| Qualcomm | Wcd9380 Firmware | All versions |
| Qualcomm | Wcd9375 Firmware | All versions |
| Qualcomm | Wcd9370 Firmware | All versions |
| Qualcomm | Wcd9341 Firmware | All versions |
| Qualcomm | Talynplus Firmware | All versions |
| Qualcomm | Sxr2130 Firmware | All versions |
| Qualcomm | Sw5100p Firmware | All versions |
| Qualcomm | Sw5100 Firmware | All versions |
| Qualcomm | Snapdragon Xr2 5g Platform Firmware | All versions |
| Qualcomm | Snapdragon X55 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon Wear 4100\+ Platform Firmware | All versions |
| Qualcomm | Snapdragon W5\+ Gen 1 Wearable Platform Firmware | All versions |
| Qualcomm | Snapdragon 870 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 865\+ 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 865 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 768g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 765g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 765 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 750g 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 690 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Sm7250p Firmware | All versions |
| Qualcomm | Sdx55 Firmware | All versions |
| Qualcomm | Sd865 5g Firmware | All versions |
| Qualcomm | Sa9000p Firmware | All versions |
| Qualcomm | Sa8540p Firmware | All versions |
| Qualcomm | Sa8530p Firmware | All versions |
| Qualcomm | Sa8295p Firmware | All versions |
| Qualcomm | Sa8195p Firmware | All versions |
| Qualcomm | Sa8155p Firmware | All versions |
| Qualcomm | Sa8150p Firmware | All versions |
| Qualcomm | Sa8145p Firmware | All versions |
| Qualcomm | Sa6155p Firmware | All versions |
| Qualcomm | Sa6150p Firmware | All versions |
| Qualcomm | Sa6145p Firmware | All versions |
| Qualcomm | Video Collaboration Vc3 Platform Firmware | All versions |
Showing 50 of 69 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-33032?
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
How severe is CVE-2024-33032?
CVE-2024-33032 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.10% probability of exploitation in the next 30 days.
How do I fix CVE-2024-33032?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-33027Memory corruption can occur when arbitrary user-space app ga…7.8
- CVE-2024-33028Memory corruption as fence object may still be accessed in t…7.8
- CVE-2024-33029Memory corruption while handling the PDR in driver for getti…6.7
- CVE-2024-3303An issue was discovered in GitLab EE affecting all versions …5.7
- CVE-2024-33030Memory corruption while parsing IPC frequency table paramete…6.7
- CVE-2024-33031Memory corruption while processing the update SIM PB records…6.7
- CVE-2024-33033Memory corruption while processing IOCTL calls to unmap the …7.8
- CVE-2024-33034Memory corruption can occur if VBOs hold outdated or invalid…7.8
- CVE-2024-33035Memory corruption while calculating total metadata size when…8.4
- CVE-2024-33036Memory corruption while parsing sensor packets in camera dri…6.7
- CVE-2024-33037Information disclosure as NPU firmware can send invalid IPC …6.1
- CVE-2024-33038Memory corruption while passing untrusted/corrupted pointers…7.8
Are you affected by CVE-2024-33032?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
