First published: Fri Sep 16 2022(Updated: )
Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm APQ8096AU Firmware | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm QCS603 | ||
Qualcomm QCS603 Firmware | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm 215 Mobile Firmware | ||
Qualcomm 215 Firmware | ||
Qualcomm SD429 | ||
Qualcomm SD429 Firmware | ||
Qualcomm SD 820 Firmware | ||
Qualcomm Snapdragon 820 | ||
Qualcomm SDM429W | ||
qualcomm SDM429W firmware | ||
Qualcomm WCD9326 | ||
Qualcomm WCD9326 Firmware | ||
Qualcomm WCD9335 Firmware | ||
Qualcomm WCD9335 Firmware | ||
Qualcomm WCD9341 | ||
Qualcomm WCD9341 Firmware | ||
Qualcomm WCN3615 Firmware | ||
Qualcomm WCN3615 Firmware | ||
Qualcomm WCN3620 Firmware | ||
Qualcomm WCN3620 Firmware | ||
Qualcomm WCN3660B | ||
Qualcomm WCN3660B Firmware | ||
Qualcomm WCN3680B Firmware | ||
Qualcomm WCN3680B Firmware | ||
Qualcomm Wcn3980 | ||
Qualcomm WCN3980 | ||
Qualcomm WCN3990 | ||
Qualcomm WCN3990 | ||
Qualcomm WSA8810 | ||
Qualcomm WSA8810 Firmware | ||
Qualcomm WSA8815 Firmware | ||
Qualcomm WSA8815 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25654 is a vulnerability that causes memory corruption in the kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables.
CVE-2022-25654 has a severity value of 6.7, which is considered medium.
CVE-2022-25654 affects the Qualcomm Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Wearables platforms.
To fix CVE-2022-25654, it is recommended to apply the security patch provided by Qualcomm. Refer to the official bulletin for more information.
CVE-2022-25654 is associated with CWE-20 and CWE-787.