Double Free in Qualcomm products - CVE-2022-25750

 

Double Free in Qualcomm products - CVE-2022-25750

Published: October 3, 2022


Vulnerability identifier: #VU67834
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-25750
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Qualcomm
Affected software:
Kailua
SG8275
SG8275P
SM8550
WCD9380
WCD9385
WCD9390
WCD9395
WCN6855
WCN6856
WCN7850
WCN7851
WSA8840
WSA8845
WSA8845H

Detailed vulnerability description

The vulnerability allows an attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within Bluetooth HOST while music playback and calls over bluetooth headset. An attacker with physical proximity to device can trigger a double free error and execute arbitrary code on the target system.



How to mitigate CVE-2022-25750

Install updates from vendor's website.

Sources