Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-45569

CVE-2024-45569: Qualcomm AR8035 Buffer Overflow Flaw

CVE-2024-45569 is a buffer overflow vulnerability in Qualcomm AR8035 Firmware caused by memory corruption while parsing ML IE due to invalid frame content. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2024-45569 Overview

CVE-2024-45569 is a memory corruption vulnerability in Qualcomm wireless firmware affecting how the WLAN host driver parses the Multi-Link Information Element (ML IE) in 802.11 frames. The flaw stems from improper validation of array index values [CWE-129] when processing attacker-controlled frame content. An unauthenticated remote attacker within wireless range can transmit a malformed frame to trigger memory corruption in the receiving device. The vulnerability impacts a broad range of Snapdragon mobile, automotive, compute, and FastConnect platforms, including the Snapdragon 8 Gen 2 and Gen 3 Mobile Platforms.

Critical Impact

Remote, unauthenticated memory corruption in WLAN firmware exposing hundreds of Qualcomm chipsets across mobile, automotive, IoT, and networking products to potential code execution or denial of service.

Affected Products

  • Qualcomm Snapdragon 8 Gen 2 and Gen 3 Mobile Platforms (firmware)
  • Qualcomm FastConnect 6700, 6900, and 7800 connectivity systems
  • Qualcomm IPQ, QCN, QCA, and WCN series wireless and networking firmware

Discovery Timeline

  • 2025-02-03 - CVE CVE-2024-45569 published to NVD
  • 2025-02-05 - Last updated in NVD database

Technical Details for CVE-2024-45569

Vulnerability Analysis

The vulnerability resides in the WLAN host firmware logic that parses the Multi-Link Information Element (ML IE) used by 802.11be (Wi-Fi 7) multi-link operation. The parser fails to validate array index values derived from fields inside an attacker-supplied frame. When a malformed ML IE is processed, the code uses untrusted length or index data to access memory regions beyond the intended bounds, resulting in memory corruption.

Because the affected component is firmware that handles raw wireless frames before user-mode interaction occurs, exploitation requires no authentication, no privileges, and no user action. An attacker within radio range of a vulnerable device can craft and broadcast frames containing malicious ML IE structures to corrupt firmware memory. Successful exploitation can lead to denial of service or, in worst-case scenarios, arbitrary code execution within the wireless subsystem.

Root Cause

The root cause is improper validation of an array index [CWE-129] during ML IE parsing. The WLAN firmware trusts length and identifier fields embedded within received frames without validating them against allocated buffer sizes or expected element bounds.

Attack Vector

The attack vector is wireless network adjacency. An attacker transmits a specially crafted 802.11 management or control frame containing an invalid ML IE to a target device. No association, authentication, or user interaction is required. The malformed frame is processed by the WLAN firmware parser, triggering the out-of-bounds memory access.

No public proof-of-concept exploit code has been released for CVE-2024-45569, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Technical details of the parsing flaw are described in the Qualcomm Security Bulletin February 2025.

Detection Methods for CVE-2024-45569

Indicators of Compromise

  • Unexpected WLAN driver or firmware crashes, kernel panics, or device reboots correlated with periods of nearby wireless activity.
  • Repeated reception of malformed 802.11 beacon, probe response, or association frames containing oversized or malformed Multi-Link Information Elements.
  • Anomalous wireless subsystem log entries referencing ML IE parsing errors or buffer faults.

Detection Strategies

  • Monitor wireless packet captures for non-conformant 802.11be ML IE structures, particularly those with inconsistent length fields or out-of-spec sub-element counts.
  • Correlate firmware crash reports and kernel logs from mobile, automotive, and IoT fleets against the affected Qualcomm chipset inventory.
  • Track vendor patch level (Android security patch level, Qualcomm firmware version) across managed devices and flag those still vulnerable.

Monitoring Recommendations

  • Centralize and review device crash telemetry to identify clustering of WLAN-related faults in time or location.
  • Deploy wireless intrusion detection sensors capable of decoding 802.11be management frames to alert on malformed ML IE content.
  • Maintain an inventory of affected Qualcomm chipsets and continuously map it against the Qualcomm Security Bulletin patch status.

How to Mitigate CVE-2024-45569

Immediate Actions Required

  • Apply the Qualcomm firmware updates referenced in the Qualcomm Security Bulletin February 2025 as soon as device OEMs distribute them.
  • Identify all assets containing affected Snapdragon, FastConnect, QCA, QCN, IPQ, and WCN components and prioritize patch deployment for internet-facing and mobile devices.
  • Coordinate with mobile device, automotive, and OEM vendors to obtain downstream firmware builds incorporating the Qualcomm fix.

Patch Information

Qualcomm has published patched firmware for the affected chipsets in its February 2025 Security Bulletin. Mobile OEMs typically ship the fix through their monthly Android security patch level updates. Automotive, networking, and IoT vendors integrate the fix into product-specific firmware releases. Confirm patch presence by validating the security patch level against the bulletin entry for CVE-2024-45569.

Workarounds

  • Disable Wi-Fi on affected devices in high-risk environments where patches are not yet available.
  • Restrict device usage to controlled wireless networks and avoid connecting to untrusted SSIDs or operating in dense public Wi-Fi areas.
  • Where supported, disable 802.11be (Wi-Fi 7) multi-link operation features that exercise the ML IE parser until firmware updates are applied.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.