CVE-2024-38420
📋 TL;DR
This vulnerability allows memory corruption when configuring a hypervisor-based input virtual device, potentially enabling arbitrary code execution or system compromise. It affects systems using Qualcomm hypervisor technology with vulnerable firmware versions.
💻 Affected Systems
- Qualcomm hypervisor implementations
📦 What is this software?
Snapdragon 765 5g Mobile Firmware by Qualcomm
Snapdragon 765g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 765g 5g Mobile Firmware →
Snapdragon 768g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 768g 5g Mobile Firmware →
Snapdragon 8 Gen 1 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 1 Mobile Firmware →
Snapdragon 8 Gen 3 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 3 Mobile Firmware →
Snapdragon 850 Mobile Compute Firmware by Qualcomm
View all CVEs affecting Snapdragon 850 Mobile Compute Firmware →
Snapdragon 865 5g Mobile Firmware by Qualcomm
Snapdragon 865 5g Mobile Firmware by Qualcomm
Snapdragon 870 5g Mobile Firmware by Qualcomm
Snapdragon 888 5g Mobile Firmware by Qualcomm
Snapdragon 888 5g Mobile Firmware by Qualcomm
Snapdragon Auto 5g Modem Rf Gen 2 Firmware by Qualcomm
View all CVEs affecting Snapdragon Auto 5g Modem Rf Gen 2 Firmware →
Snapdragon X24 Lte Modem Firmware by Qualcomm
Snapdragon X35 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X35 5g Modem Rf Firmware →
Snapdragon X50 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X50 5g Modem Rf Firmware →
Snapdragon X55 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X55 5g Modem Rf Firmware →
Snapdragon X62 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X62 5g Modem Rf Firmware →
Snapdragon X65 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X65 5g Modem Rf Firmware →
Snapdragon X72 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X72 5g Modem Rf Firmware →
Snapdragon X75 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X75 5g Modem Rf Firmware →
Video Collaboration Vc3 Platform Firmware by Qualcomm
View all CVEs affecting Video Collaboration Vc3 Platform Firmware →
Vision Intelligence 300 Firmware by Qualcomm
Vision Intelligence 400 Firmware by Qualcomm
⚠️ Risk & Real-World Impact
Worst Case
Full system compromise allowing attacker to execute arbitrary code at hypervisor level, potentially escaping guest VMs and compromising the host system.
Likely Case
Denial of service through system crashes or instability, with potential for limited code execution within the hypervisor context.
If Mitigated
Limited impact if proper isolation and access controls prevent unauthorized configuration attempts.
🎯 Exploit Status
Requires hypervisor configuration privileges; memory corruption vulnerabilities can be complex to exploit reliably but pose significant risk if successfully weaponized.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Check Qualcomm February 2025 security bulletin for specific patched versions
Vendor Advisory: https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html
Restart Required: No
Instructions:
1. Review Qualcomm February 2025 security bulletin. 2. Identify affected firmware versions. 3. Apply vendor-provided firmware updates. 4. Verify update completion and system stability.
🔧 Temporary Workarounds
Restrict hypervisor configuration access
allLimit which users/processes can configure hypervisor virtual devices to reduce attack surface
Disable unnecessary virtual devices
allDisable hypervisor-based input virtual devices that are not required for system operation
🧯 If You Can't Patch
- Implement strict access controls to prevent unauthorized hypervisor configuration
- Monitor for abnormal hypervisor configuration attempts and system crashes
🔍 How to Verify
Check if Vulnerable:
Check firmware version against Qualcomm's affected versions list in February 2025 bulletin
Check Version:
System-specific command to check Qualcomm firmware/hypervisor version (varies by device/platform)
Verify Fix Applied:
Verify firmware version matches patched version from Qualcomm bulletin and test hypervisor configuration functionality
📡 Detection & Monitoring
Log Indicators:
- Hypervisor configuration errors
- System crashes during device configuration
- Memory access violations in hypervisor logs
Network Indicators:
- Unusual hypervisor management traffic patterns
SIEM Query:
Search for hypervisor configuration events followed by system crashes or memory violation alerts