Infinite loop in Qualcomm products - CVE-2022-25742
Published: November 7, 2022
Vulnerability identifier: #VU69023
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25742
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in modem when parsing IGMPv2 packets. A remote attacker can send specially crafted traffic to the device and consume all available system resources.
Affected software
QCA4020
WSA8815
WSA8810
WCN3999
WCN3998
WCN3980
WCD9335
WCD9330
WCD9306
QCA4024
AR8031
QCA4010
QCA4004
MDM9207
MDM9205
MDM8207
CSRA6640
CSRA6620
QCS405
MDM9607
MDM9206
WSA8815
WSA8810
WCN3999
WCN3998
WCN3980
WCD9335
WCD9330
WCD9306
QCA4024
AR8031
QCA4010
QCA4004
MDM9207
MDM9205
MDM8207
CSRA6640
CSRA6620
QCS405
MDM9607
MDM9206
How to mitigate CVE-2022-25742
Install updates from vendor's website.