Intel i915 GPU: LPAC enables outofbound register access
CVE-2024-23351 Published on May 6, 2024

Improper Access Control in Graphics Linux
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

NVD

Vulnerability Analysis

CVE-2024-23351 can be exploited with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2024-23351 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2024-23351

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2024-23351 are published in these products:

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Qualcomm, Inc. Snapdragon: qualcomm fastconnect_6200_firmware: qualcomm fastconnect_6700_firmware: qualcomm fastconnect_6900_firmware: qualcomm fastconnect_7800_firmware: qualcomm flight_rb5_5g_platform_firmware: qualcomm qam8255p_firmware: qualcomm qam8295p_firmware: qualcomm qam8650p_firmware: qualcomm qam8775p_firmware: qualcomm qamsrv1h_firmware: qualcomm qamsrv1m_firmware: qualcomm qca6391_firmware: qualcomm qca6574_firmware: qualcomm qca6574a_firmware: qualcomm qca6574au_firmware: qualcomm qca6595_firmware: qualcomm qca6595au_firmware: qualcomm qca6678aq_firmware: qualcomm qca6696_firmware: qualcomm qca6698aq_firmware: qualcomm qca6797aq_firmware: qualcomm qcm4325_firmware: qualcomm qcm4490_firmware: qualcomm qcm5430_firmware: qualcomm qcm6125_firmware: qualcomm qcm6490_firmware: qualcomm qcm8550_firmware: qualcomm qcs4490_firmware: qualcomm qcs5430_firmware: qualcomm qcs6125_firmware: qualcomm qcs6490_firmware: qualcomm qcs7230_firmware: qualcomm qcs8250_firmware: qualcomm qcs8550_firmware: qualcomm qrb5165n_firmware: qualcomm_video_collaboration_vc1_platform_firmware: qualcomm_video_collaboration_vc3_platform_firmware: qualcomm_video_collaboration_vc5_platform_firmware: qualcomm robotics_rb5_platform_firmware: qualcomm sa6155p_firmware:

Exploit Probability

EPSS
0.08%
Percentile
24.17%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.