CVE-2022-22265: Samsung Mobile Devices Use-After-Free Vulnerability
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
Other sources
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NPU driverto a version that resolves this vulnerability.Fixed in SMR Jan-2022 Release 1 - Compensating control
Discontinue use of the affected Samsung mobile device if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2022-22265?
CVE-2022-22265 is a use-after-free vulnerability found in Samsung mobile devices with selected Exynos chipsets.
How does CVE-2022-22265 affect Samsung mobile devices?
CVE-2022-22265 allows for malicious memory write and code execution on Samsung mobile devices with selected Exynos chipsets.
What is the severity of CVE-2022-22265?
The severity of CVE-2022-22265 is not available.
How can I fix CVE-2022-22265?
To fix CVE-2022-22265, it is recommended to install the security update provided by Samsung.
Where can I find more information about CVE-2022-22265?
You can find more information about CVE-2022-22265 on the Samsung Mobile Security Updates website.