CVE-2022-22057
Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- qualcomm/apq8053 firmware · qualcomm/ar8035 firmware · qualcomm/msm8953 firmware · qualcomm/qca6174a firmware · qualcomm/qca6390 firmware · qualcomm/qca6391 firmware · qualcomm/qca6426 firmware · qualcomm/qca6436 firmware · qualcomm/qca6595au firmware · qualcomm/qca8081 firmware · qualcomm/qca8337 firmware · qualcomm/qca9377 firmware · qualcomm/qcm2290 firmware · qualcomm/qcm4290 firmware · qualcomm/qcm6490 firmware · qualcomm/qcs2290 firmware · qualcomm/qcs4290 firmware · qualcomm/qcs6490 firmware · qualcomm/qrb5165 firmware · qualcomm/qrb5165m firmware · +40 more
- Source
- product-security@qualcomm.com
References
- http://packetstormsecurity.com/files/172850/Qualcomm-kgsl-Driver-Use-After-Free.html
- https://www.qualcomm.com/company/product-security/bulletins/may-2022-bulletinPatch, Vendor Advisory
- http://packetstormsecurity.com/files/172850/Qualcomm-kgsl-Driver-Use-After-Free.html
- https://www.qualcomm.com/company/product-security/bulletins/may-2022-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.