CVE-2022-22095
Memory corruption in synx driver due to use-after-free condition in the synx driver due to accessing object handles without acquiring lock in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Memory corruption in synx driver due to use-after-free condition in the synx driver due to accessing object handles without acquiring lock in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- qualcomm/apq8053 firmware · qualcomm/msm8953 firmware · qualcomm/qca6390 firmware · qualcomm/qca6391 firmware · qualcomm/qca6426 firmware · qualcomm/qca6436 firmware · qualcomm/qcm2290 firmware · qualcomm/qcm4290 firmware · qualcomm/qcs2290 firmware · qualcomm/qcs4290 firmware · qualcomm/qrb5165 firmware · qualcomm/qrb5165m firmware · qualcomm/qrb5165n firmware · qualcomm/sd439 firmware · qualcomm/sd460 firmware · qualcomm/sd662 firmware · qualcomm/sd680 firmware · qualcomm/sd690 5g firmware · qualcomm/sd750g firmware · qualcomm/sd765 firmware · +29 more
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.