CVE-2022-22071
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 26 December 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.46% probability · 38th percentile
- CISA KEV
- Listed 5 December 2023 · due 26 December 2023
- Weakness
- CWE-416
- Affected
- qualcomm/apq8053 firmware · qualcomm/ar8031 firmware · qualcomm/ar8035 firmware · qualcomm/csra6620 firmware · qualcomm/csra6640 firmware · qualcomm/mdm9150 firmware · qualcomm/msm8953 firmware · qualcomm/qca6174a firmware · qualcomm/qca6390 firmware · qualcomm/qca6391 firmware · qualcomm/qca6426 firmware · qualcomm/qca6436 firmware · qualcomm/qca6574 firmware · qualcomm/qca6574a firmware · qualcomm/qca6574au firmware · qualcomm/qca6595au firmware · qualcomm/qca6696 firmware · qualcomm/qca8081 firmware · qualcomm/qca8337 firmware · qualcomm/qca9377 firmware · +40 more
- Source
- product-security@qualcomm.com
CISA notes
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-5.4/-/commit/586840fde350d7b8563df9889c8ce397e2c20dda; https://nvd.nist.gov/vuln/detail/CVE-2022-22071
References
- https://www.qualcomm.com/company/product-security/bulletins/may-2022-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/may-2022-bulletinPatch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22071US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.