Memory Corruption in Graphics of Qualcomm Snapdragon Products
CVE-2022-25743

8.4HIGH

Summary

A vulnerability exists in the Qualcomm Snapdragon product line where improper memory management during the import of graphics buffers can lead to memory corruption. This occurs due to a use-after-free condition, which may allow an attacker to execute arbitrary code or cause denial of service by manipulating how memory is allocated and used. Devices utilizing Snapdragon technology for various applications are at risk, necessitating immediate attention to implement available patches and updates.

Affected Version(s)

Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables APQ8009

Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables APQ8009W

Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables APQ8017

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.