CVE-2022-25666
Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired…
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- qualcomm/apq8096au firmware · qualcomm/aqt1000 firmware · qualcomm/ar9380 firmware · qualcomm/csr8811 firmware · qualcomm/ipq4018 firmware · qualcomm/ipq4019 firmware · qualcomm/ipq4028 firmware · qualcomm/ipq4029 firmware · qualcomm/ipq5010 firmware · qualcomm/ipq5018 firmware · qualcomm/ipq5028 firmware · qualcomm/ipq6010 firmware · qualcomm/ipq6018 firmware · qualcomm/ipq6028 firmware · qualcomm/ipq8064 firmware · qualcomm/ipq8065 firmware · qualcomm/ipq8068 firmware · qualcomm/ipq8070 firmware · qualcomm/ipq8070a firmware · qualcomm/ipq8071a firmware · +40 more
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/october-2022-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/october-2022-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.