Untrusted Pointer Dereference in Qualcomm products - CVE-2022-40533

 

Untrusted Pointer Dereference in Qualcomm products - CVE-2022-40533

Published: June 5, 2023


Vulnerability identifier: #VU76864
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40533
CWE-ID: CWE-822
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in Core. A local application can perform a denial of service (DoS) attack.


Affected software

Snapdragon 750G 5G Mobile Platform
Snapdragon 870 5G Mobile Platform (SM8250-AC)
Snapdragon 865+ 5G Mobile Platform (SM8250-AB)
Snapdragon 865 5G Mobile Platform
Snapdragon 8+ Gen 1 Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 7c+ Gen 3 Compute
Snapdragon 782G Mobile Platform (SM7325-AF)
Snapdragon 780G 5G Mobile Platform
Snapdragon 778G+ 5G Mobile Platform (SM7325-AE)
Snapdragon 778G 5G Mobile Platform
Snapdragon 768G 5G Mobile Platform (SM7250-AC)
Snapdragon 765G 5G Mobile Platform (SM7250-AB)
Snapdragon 765 5G Mobile Platform (SM7250-AA)
Snapdragon 888 5G Mobile Platform
Snapdragon 720G Mobile Platform
Snapdragon 690 5G Mobile Platform
Snapdragon 685 4G Mobile Platform (SM6225-AD)
Snapdragon 680 4G Mobile Platform
Snapdragon 662 Mobile Platform
Snapdragon 460 Mobile Platform
Smart Audio 400 Platform
SM7325P
SM7315
SM7250P
SM6250P
SM6250
WCD9335
WSA8835
WSA8830
WSA8815
WSA8810
WCN6740
WCN3988
WCN3950
WCN3910
WCD9385
WCD9380
WCD9375
WCD9370
SM4450
SXR2230P
SXR1230P
SSG2125P
SSG2115P
Snapdragon XR2+ Gen 1 Platform
Snapdragon XR2 5G Platform
Snapdragon X55 5G Modem-RF System
Snapdragon AR2 Gen 1 Platform
BB)
Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
QCA6421
QCM4490
QCM4325
QCM4290
QCM2290
QCA6797AQ
QCA6698AQ
QCA6696
QCA6595AU
QCA6595
QCA6436
QCA6431
QCA6426
QCM6490
QCA6391
QAM8775P
QAM8650P
QAM8295P
QAM8255P
Flight RB5 5G Platform
FastConnect 7800
FastConnect 6900
FastConnect 6800
FastConnect 6700
FastConnect 6200
CSRA6640
Robotics RB5 Platform
SM4125
SG4150P
SD865 5G
SD662
SD460
SD 8 Gen1 5G
SA8295P
SA8255P
CSRA6620
QSM8350
QSM8250
QRB5165N
QRB5165M
QCS8550
QCS8250
QCS6490
QCS4490
QCS4290
QCS2290
QCN9012
QCN9011
WSA8832
SXR2130
QCA6574AU
SDX55
SD888
SA9000P
SA8540P
Google Android

How to mitigate CVE-2022-40533

Install security update from vendor's website.

Google Android - addressed in versions 11 2023-06-05, 12L 2023-06-05, 12 2023-06-05, 13 2023-06-05

External References

Related Security Bulletins