Out-of-bounds read in Qualcomm products - CVE-2022-25653

 

Out-of-bounds read in Qualcomm products - CVE-2022-25653

Published: September 8, 2022


Vulnerability identifier: #VU67085
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25653
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition when processing AVI files. A remote attacker can create a specially crafted AVI file, trick the victim into playing it, trigger an out-of-bounds read error and read contents of memory on the system or crash the application.


Affected software

SW5100
WCN3660B
WCN3620
WCN3615
WCD9385
WCD9380
WCD9375
WCD9370
WCD9341
WCD9335
WCD9326
SW5100P
WCN3680
SM7325P
SM7315
SM7250P
SM6250
SM4125
SDXR2 5G
SDX55M
WCN6850
WSA8835
WSA8830
WSA8815
WSA8810
WCN7851
WCN7850
WCN6856
WCN6855
WCN6851
WCN6750
WCN6740
WCN3998
WCN3991
WCN3990
WCN3988
WCN3980
WCN3950
WCN3910
WCN3680B
QCS410
SD480
SD460
SD429
SD 8 Gen1 5G
SD 675
Qualcomm215
QCS6490
QCS610
QCS603
QCS4290
SD662
QCM6490
QCM4290
QCA6436
QCA6430
QCA6426
QCA6420
QCA6391
QCA6390
AQT1000
SD765G
SDX50M
SD888 5G
SD870
SD865 5G
SD780G
SD778G
SD768G
SD765
SD750G
SD720G
SD695
SD690 5G
SD680
SD678
Pixel
SM8475P
SM8475
SM7450
WSA8832
SDX55
QCS605
MSM8953
SDM429W
SD888
SD855
APQ8053
SD730
SD675
SD665

How to mitigate CVE-2022-25653

Install updates from vendor's website.

Pixel - update to 12L 2022-09-05

External References

Related Security Bulletins