Resource exhaustion in Qualcomm products - CVE-2022-33303
Published: June 5, 2023
Vulnerability identifier: #VU76883
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33303
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation in Linux kernel. A local application can perform a denial of service (DoS) attack.
Affected software
SA8150P
WSA8835
WSA8830
WCD9385
WCD9380
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Snapdragon 888 5G Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
SA8195P
SA8155P
FastConnect 6900
SA8145P
SA6150P
SA6145P
QCA6696
QCA6595AU
FastConnect 7800
Pixel
SA6155P
QCA6574AU
WSA8835
WSA8830
WCD9385
WCD9380
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Snapdragon 888 5G Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
SA8195P
SA8155P
FastConnect 6900
SA8145P
SA6150P
SA6145P
QCA6696
QCA6595AU
FastConnect 7800
Pixel
SA6155P
QCA6574AU
How to mitigate CVE-2022-33303
Install security update from vendor's website.
Pixel - update to 2023-06-05