CVE-2022-25731: Incorrect Calculation of Buffer Size in MODEM
Information disclosure in modem due to buffer over-read while processing packets from DNS server
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25731?
CVE-2022-25731 is a vulnerability that allows information disclosure in a modem due to a buffer over-read while processing packets from a DNS server.
Which software is affected by CVE-2022-25731?
The software affected by CVE-2022-25731 is Qualcomm Mdm9205 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9207 Firmware, Qualcomm Mdm8207 Firmware, Qualcomm Qca4004 Firmware, Qualcomm Qca4010 Firmware, Qualcomm Qts110 Firmware, Qualcomm Snapdragon Wear 1300 Firmware, Qualcomm Snapdragon X5 Lte Modem Firmware, Qualcomm Wcd9330 Firmware, and Qualcomm Wcd9306 Firmware.
What is the severity of CVE-2022-25731?
CVE-2022-25731 has a severity level of 7.5 (High).
How does CVE-2022-25731 work?
CVE-2022-25731 works by exploiting a buffer over-read vulnerability in the modem while processing packets from a DNS server, leading to information disclosure.
Is there a fix available for CVE-2022-25731?
To fix CVE-2022-25731, it is recommended to apply the necessary security patches provided by Qualcomm.