Buffer overflow in Qualcomm products - CVE-2022-25654
Published: September 8, 2022
Vulnerability identifier: #VU67092
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25654
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error when processing ION commands within kernel. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
Affected software
WCD9326
WSA8815
WSA8810
WCN3990
WCN3980
WCN3680
WCN3660B
WCN3620
WCN3615
WCD9341
WCD9335
SD820
SD429
Qualcomm215
QCS603
Pixel
APQ8096AU
SDM429W
QCS605
QCA6574AU
QCA6174A
MDM9650
WSA8815
WSA8810
WCN3990
WCN3980
WCN3680
WCN3660B
WCN3620
WCN3615
WCD9341
WCD9335
SD820
SD429
Qualcomm215
QCS603
Pixel
APQ8096AU
SDM429W
QCS605
QCA6574AU
QCA6174A
MDM9650
How to mitigate CVE-2022-25654
Install updates from vendor's website.
Pixel - update to 12L 2022-09-05