Buffer overflow in Qualcomm products - CVE-2022-25654

 

Buffer overflow in Qualcomm products - CVE-2022-25654

Published: September 8, 2022


Vulnerability identifier: #VU67092
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25654
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing ION commands within kernel. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.


Affected software

WCD9326
WSA8815
WSA8810
WCN3990
WCN3980
WCN3680
WCN3660B
WCN3620
WCN3615
WCD9341
WCD9335
SD820
SD429
Qualcomm215
QCS603
Pixel
APQ8096AU
SDM429W
QCS605
QCA6574AU
QCA6174A
MDM9650

How to mitigate CVE-2022-25654

Install updates from vendor's website.

Pixel - update to 12L 2022-09-05

External References

Related Security Bulletins