Incorrect Type Conversion or Cast (Type Conversion) in Qualcomm products - CVE-2022-25715
Published: January 10, 2023
Vulnerability identifier: #VU71029
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25715
CWE-ID: CWE-704
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in Display driver. A local privileged application can execute arbitrary code.
Affected software
SD855
SDX55
SDM429W
SD210
SD205
QCS8155
MDM9150
WSA8815
WSA8810
WCN3998
WCN3980
WCN3950
WCN3680B
WCN3660B
WCN3620
WCN3610
WCD9370
WCD9341
WCD9340
SDA429W
AQT1000
SD429
SA8155P
SA515M
Qualcomm215
QCS610
QCS410
QCN9074
QCA8337
QCA6430
QCA6420
QCA6391
Pixel
SDX55
SDM429W
SD210
SD205
QCS8155
MDM9150
WSA8815
WSA8810
WCN3998
WCN3980
WCN3950
WCN3680B
WCN3660B
WCN3620
WCN3610
WCD9370
WCD9341
WCD9340
SDA429W
AQT1000
SD429
SA8155P
SA515M
Qualcomm215
QCS610
QCS410
QCN9074
QCA8337
QCA6430
QCA6420
QCA6391
Pixel
How to mitigate CVE-2022-25715
Install security update from vendor's website.
Pixel - update to 2023-01-05