Memory Corruption Vulnerability in Qualcomm Snapdragon Products
CVE-2022-25681

8.4HIGH

Summary

A memory corruption vulnerability exists in Qualcomm's Snapdragon product line, which could lead to improper handling of memory access. The issue arises from the hypervisor failing to correctly invalidate processor translation caches, potentially impacting the security and stability of devices utilizing Snapdragon Auto, Compute, Consumer IoT, Industrial IoT, and Mobile platforms. Users are encouraged to follow security advisories to mitigate any risks associated with this vulnerability.

Affected Version(s)

Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile AQT1000

Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile AR8035

Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile QAM8295P

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.