Use After Free in Qualcomm products - CVE-2022-33225

 

Use After Free in Qualcomm products - CVE-2022-33225

Published: February 7, 2023


Vulnerability identifier: #VU71964
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33225
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Trusted Application Environment. A local privileged application can execute arbitrary code.


Affected software

SD429
WSA8815
WSA8810
WCN6851
WCN6850
WCN3660B
WCN3620
WCN3610
WCD9380
WCD9340
SDXR2 5G
SDX55M
SD870
SD865 5G
Qualcomm215
QCA6574A
QCA6564AU
QCA6564A
QCA6436
QCA6426
QCA6391
QCA6390
MDM9628
Pixel
SDM429W
APQ8096AU
SD210
SD205
QCA6574AU
MSM8996AU

How to mitigate CVE-2022-33225

Install security update from vendor's website.

Pixel - update to 2023-02-05

External References

Related Security Bulletins