CVE-2022-33303: Uncontrolled resource consumption in Linux kernel
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-33303?
CVE-2022-33303 is a vulnerability in the Linux kernel that allows for transient denial-of-service attacks due to uncontrolled resource consumption when malformed messages are sent from the Gunyah Resource Manager message queue.
How severe is CVE-2022-33303?
CVE-2022-33303 has a severity level of 5.5, which is considered medium.
Which software is affected by CVE-2022-33303?
Qualcomm Wcn685x-5 Firmware, Qualcomm Wcn685x-1 Firmware, Qualcomm Wcn785x-1 Firmware, Qualcomm Wcn785x-5 Firmware, Google Android, Qualcomm Qca6574au, Qualcomm Qca6595au, Qualcomm Qca6696, Qualcomm Sa6145p, Qualcomm Sa6150p Firmware, Qualcomm Sa6155p, Qualcomm Sa8145p Firmware, Qualcomm Sa8150p, Qualcomm Sa8195p Firmware, Qualcomm Sm8450 Firmware, Qualcomm Sm8350 Firmware, Qualcomm Sm8350-ac Firmware, Qualcomm Wcd9380, Qualcomm Wcd9385, Qualcomm Wsa8830, and Qualcomm Wsa8835 are affected by CVE-2022-33303.
How do I fix CVE-2022-33303?
To fix CVE-2022-33303, it is recommended to apply the necessary updates and patches provided by Qualcomm. Please refer to the official Qualcomm product security bulletin for more information.
What is the Common Weakness Enumeration (CWE) ID of CVE-2022-33303?
The Common Weakness Enumeration (CWE) ID of CVE-2022-33303 is CWE-400.