Out-of-bounds read in Qualcomm products - CVE-2022-25663
Published: October 3, 2022
Vulnerability identifier: #VU67821
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25663
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the WLAN Windows Host component. A local application can trigger an out-of-bounds read and perform a denial of service (DoS) attack.
Affected software
SD850
WSA8835
WSA8830
WSA8815
WSA8810
WCN6856
WCN6855
WCN6750
WCN3998
WCN3991
WCN3990
WCD9385
WCD9380
WCD9341
WCD9340
SM6250
AQT1000
SD7c
SD778G
SD 8cx Gen3
SD 8cx Gen2
QCA6430
QCA6420
QCA6391
QCA6390
QCA2066
QCA2065
QCA2064
QCA2062
QCA1064
QCA1062
WSA8835
WSA8830
WSA8815
WSA8810
WCN6856
WCN6855
WCN6750
WCN3998
WCN3991
WCN3990
WCD9385
WCD9380
WCD9341
WCD9340
SM6250
AQT1000
SD7c
SD778G
SD 8cx Gen3
SD 8cx Gen2
QCA6430
QCA6420
QCA6391
QCA6390
QCA2066
QCA2065
QCA2064
QCA2062
QCA1064
QCA1062
How to mitigate CVE-2022-25663
Install updates from vendor's website.