Use-after-free in Qualcomm products - CVE-2022-22058

 

Use-after-free in Qualcomm products - CVE-2022-22058

Published: July 7, 2022


Vulnerability identifier: #VU64973
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22058
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in kernel while processing ION handles. A local application can trigger a use-after-free error and execute arbitrary code with elevated privileges.


Affected software

SD632
SDW2500
SD820
SD660
SD439
SD429
SA415M
Qualcomm215
QCS603
QCN7606
WCN3620
WSA8815
WSA8810
WCN3998
WCN3990
WCN3980
WCN3680B
WCN3680
WCN3660B
WCN3660
WCN3615
WCN3610
WCD9341
WCD9340
WCD9335
WCD9330
WCD9326
SDXR1
MDM9628
MDM9626
PM8937
MDM9250
CSRB31024
AQT1000
APQ8009W
QCA6564A
QCA9367
QCA6696
QCA6595AU
QCA6584
QCA6574A
QCA6574
QCA6564AU
QCA6430
QCA6420
QCA6335
QCA6320
QCA6310
QCA6175A
QCA4020
SDM429W
SD855
SD845
SD835
SD710
SD670
SDX20
SD450
QCS605
QCN7605
QCA9379
SDX24
MDM9607
MSM8996AU
MSM8953
MSM8937
MSM8917
MSM8909W
MDM9650
MDM9640
MDM9206
MDM9150
APQ8096AU
APQ8053
APQ8017
QCA9377
QCA6574AU
APQ8009
QCA6174A
Google Android

How to mitigate CVE-2022-22058

Install updates from vendor's website.

Google Android - addressed in versions 10 2022-07-05, 11 2022-07-05, 12L 2022-07-05, 12 2022-07-05

External References

Related Security Bulletins