First published: Tue Apr 04 2023(Updated: )
Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface
Credit: product-security@qualcomm.com product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Mdm8207 Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
Qualcomm Mdm9207 Firmware | ||
Qualcomm Mdm9207 | ||
Google Android | ||
Qualcomm Qca4004 | ||
Qualcomm Qts110 Firmware | ||
Qualcomm Qts110 | ||
Qualcomm Snapdragon Wear 1300 Firmware | ||
Qualcomm Snapdragon Wear 1300 | ||
Qualcomm Snapdragon X5 Lte Modem Firmware | ||
Qualcomm Snapdragon X5 Lte Modem | ||
Qualcomm Wcd9306 Firmware | ||
Google Android | ||
Google Android | ||
Qualcomm Wcd9330 | ||
All of | ||
Qualcomm Mdm8207 Firmware | ||
Google Android | ||
All of | ||
Google Android | ||
Google Android | ||
All of | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
All of | ||
Qualcomm Mdm9207 Firmware | ||
Qualcomm Mdm9207 | ||
All of | ||
Google Android | ||
Qualcomm Qca4004 | ||
All of | ||
Qualcomm Qts110 Firmware | ||
Qualcomm Qts110 | ||
All of | ||
Qualcomm Snapdragon Wear 1100 Firmware | ||
Qualcomm Snapdragon Wear 1100 | ||
All of | ||
Qualcomm Snapdragon Wear 1200 Firmware | ||
Qualcomm Snapdragon Wear 1200 | ||
All of | ||
Qualcomm Snapdragon Wear 1300 Firmware | ||
Qualcomm Snapdragon Wear 1300 | ||
All of | ||
Qualcomm Snapdragon X5 Lte Modem Firmware | ||
Qualcomm Snapdragon X5 Lte Modem | ||
All of | ||
Qualcomm Wcd9306 Firmware | ||
Google Android | ||
All of | ||
Google Android | ||
Qualcomm Wcd9330 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25740 is a memory corruption vulnerability in the modem that occurs due to a buffer overwrite while building an IPv6 multicast address based on the MAC address of the interface.
The Qualcomm Mdm8207 Firmware, Qualcomm Mdm9205 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9207 Firmware, Qualcomm Qca4004, Qualcomm Qts110 Firmware, Qualcomm Snapdragon Wear 1300 Firmware, and Qualcomm Wcd9330 software are affected.
CVE-2022-25740 has a severity rating of 9.8, which is classified as critical.
To fix CVE-2022-25740, it is recommended to apply the necessary firmware updates provided by Qualcomm.
You can find more information about CVE-2022-25740 on the Qualcom website in their April 2023 security bulletin.