CVE-2022-22071

CVE Published 2022-06-14
Related CWE(s) CWE-416: Use After Free
Related Vendor(s) qualcomm
Related Product(s) qca6574a_firmware, sd780g_firmware, wcn3980_firmware, mdm9150_firmware, sm7250p_firmware, wcd9380_firmware, sd778g_firmware, wcd9370_firmware, wcn3660b_firmware, qcs4290_firmware, wsa8815_firmware, sa8195p_firmware, sm7325p_firmware, qcs410_firmware, qca8081_firmware, wcn3615_firmware, wcn7850_firmware, sd480_firmware, sd870_firmware, sdx55m_firmware, qualcomm215_firmware, sa8155p_firmware, sdx65_firmware, wcn6750_firmware, qca6574au_firmware, sd460_firmware, wsa8810_firmware, wcn6851_firmware, msm8953_firmware, qcm6490_firmware, qca6426_firmware, wsa8835_firmware, wcn3680b_firmware, wcd9385_firmware, qca6174a_firmware, sd680_firmware, wcn3991_firmware, apq8053_firmware, wcn3998_firmware, qcs610_firmware, sd768g_firmware, sdx12_firmware, qrb5165_firmware, sm4125_firmware, csra6640_firmware, wcn6855_firmware, sd750g_firmware, sd690_5g_firmware, sdxr2_5g_firmware, qca8337_firmware, csra6620_firmware, wcn3950_firmware, sd888_5g_firmware, sd865_5g_firmware, wcn6850_firmware, wcd9326_firmware, wcn7851_firmware, sd695_firmware, sd439_firmware, sd662_firmware, qcm2290_firmware, wcd9341_firmware, ar8031_firmware, qcs6490_firmware, wcn3910_firmware, sd855_firmware, qca6390_firmware, sa6155p_firmware, qcs405_firmware, qca6696_firmware, qcm4290_firmware, wcn6856_firmware, qrb5165m_firmware, wcn6740_firmware, wsa8830_firmware, wcn3988_firmware, sdx55_firmware, wcd9335_firmware, sd765g_firmware, qcs2290_firmware, qca6391_firmware, qrb5165n_firmware, wcn3999_firmware, qca6436_firmware, qca9377_firmware, qca6595au_firmware, sd765_firmware, wcd9375_firmware, ar8035_firmware, qca6574_firmware
Exploitation Reported (CISA KEV) 2023-12-05
CVSS 3 Base Score 8.4 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References