#VU67090 Use-after-free in Qualcomm Hardware solutions


Published: 2022-09-08

Vulnerability identifier: #VU67090

Vulnerability risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-25693

CWE-ID: CWE-416

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
SD 8 Gen1 5G
Mobile applications / Mobile firmware & hardware
WCD9370
Mobile applications / Mobile firmware & hardware
WCD9375
Mobile applications / Mobile firmware & hardware
WCD9380
Mobile applications / Mobile firmware & hardware
WCD9385
Mobile applications / Mobile firmware & hardware
WCN6750
Mobile applications / Mobile firmware & hardware
WCN6855
Mobile applications / Mobile firmware & hardware
WCN6856
Mobile applications / Mobile firmware & hardware
WCN7851
Mobile applications / Mobile firmware & hardware
WSA8830
Mobile applications / Mobile firmware & hardware
WSA8835
Mobile applications / Mobile firmware & hardware
SM7450
Hardware solutions / Firmware
SM8475
Hardware solutions / Firmware
SM8475P
Hardware solutions / Firmware
WSA8832
Hardware solutions / Firmware

Vendor: Qualcomm

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Graphics component. A remote attacker can trick the victim to open a specially crafted file, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

SD 8 Gen1 5G: All versions

SM7450: All versions

SM8475: All versions

SM8475P: All versions

WCD9370: All versions

WCD9375: All versions

WCD9380: All versions

WCD9385: All versions

WCN6750: All versions

WCN6855: All versions

WCN6856: All versions

WCN7851: All versions

WSA8830: All versions

WSA8832: All versions

WSA8835: All versions


External links
http://docs.qualcomm.com/product/publicresources/securitybulletin/september-2022-bulletin.html
http://git.codelinaro.org/clo/la/kernel/msm-5.10/-/commit/c0d2d03debbedc696561cd7b3c503c4aeaabfa1a


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability