CVE-2022-25739: Null Point Dereference in MODEM
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25739?
CVE-2022-25739 is a vulnerability that allows for a denial of service in a modem due to a missing null check while processing the IPv6 packet received during an ECM call.
What software is affected by CVE-2022-25739?
The affected software includes Google Android, Qualcomm Mdm9205 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9207 Firmware, Qualcomm Mdm8207 Firmware, Qualcomm Qca4004, Qualcomm Qts110 Firmware, Qualcomm Snapdragon Ar2 Gen 1 Platform Firmware, Qualcomm Snapdragon X5 Lte Modem Firmware, Qualcomm Ssg2115p Firmware, Qualcomm Ssg2125p Firmware, Qualcomm Sxr1230p Firmware, Qualcomm Sxr2230p Firmware, Qualcomm Wcd9306 Firmware, Qualcomm Wcd9330, Qualcomm Wcd9380, Qualcomm Wcd9385, Qualcomm Wsa8830, Qualcomm Wsa8832 Firmware, Qualcomm Wsa8835, Qualcomm Wcn685x-1 Firmware, Qualcomm Wcn685x-5 Firmware, Qualcomm Wcn785x-1 Firmware, Qualcomm Wcn785x-5 Firmware, and Qualcomm Snapdragon Wear 1300 Firmware.
What is the severity of CVE-2022-25739?
The severity of CVE-2022-25739 is high with a CVSSv3 score of 7.5.
How can I fix CVE-2022-25739?
To fix CVE-2022-25739, it is recommended to apply the latest security updates provided by the respective software vendors.
Where can I find more information about CVE-2022-25739?
You can find more information about CVE-2022-25739 on the Qualcomm product security bulletin for April 2023.