7.5
CWE
617
Advisory Published
Updated

CVE-2022-40508

First published: Mon May 01 2023(Updated: )

Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.

Credit: product-security@qualcomm.com

Affected SoftwareAffected VersionHow to fix
Qualcomm 315 5g Iot Modem Firmware
Qualcomm 315 5g Iot Modem
Google Android
Google Android
Google Android
Qualcomm Ar8035
Google Android
Google Android
Google Android
Google Android
Qualcomm Qca6390 Firmware
Qualcomm Qca6390
Qualcomm Wcn685x-5 Firmware
Qualcomm Wcn685x-5
Qualcomm Wcn685x-1 Firmware
Qualcomm Wcn685x-1
Qualcomm Wcn785x-1 Firmware
Qualcomm Wcn785x-1
Qualcomm Wcn785x-5 Firmware
Qualcomm Wcn785x-5
Google Android
Google Android
Qualcomm Qca6421 Firmware
Qualcomm Qca6421
Qualcomm Qca6426 Firmware
Google Android
Qualcomm Qca6431 Firmware
Qualcomm Qca6431
Google Android
Qualcomm Qca6436
Google Android
Google Android
Google Android
Qualcomm Qca6574au
Google Android
Google Android
Google Android
Qualcomm Qca6696
Qualcomm Qca6698aq Firmware
Qualcomm Qca6698aq
Qualcomm Qca8081 Firmware
Google Android
Qualcomm Qca8337 Firmware
Google Android
Qualcomm Qcn6024 Firmware
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Qualcomm Sdx55 Firmware
Qualcomm Sdx55
Qualcomm Sdx57m Firmware
Google Android
Google Android
Google Android
Google Android
Qualcomm Sm7315
Qualcomm Sm4375 Firmware
Qualcomm Sm4375
Qualcomm Sm4350 Firmware
Qualcomm Sm4350
Qualcomm Sm4350-ac Firmware
Qualcomm Sm4350-ac
Qualcomm Sm6350 Firmware
Qualcomm Sm6350
Google Android
Google Android
Qualcomm Sm7225 Firmware
Qualcomm Sm7225
Qualcomm Sm7250-aa Firmware
Qualcomm Sm7250-aa
Qualcomm Sm7250-ab Firmware
Qualcomm Sm7250-ab
Qualcomm Sm7250-ac Firmware
Qualcomm Sm7250-ac
Qualcomm Sm7350-ab Firmware
Qualcomm Sm7350-ab
Qualcomm Snapdragon 7c\+ Gen 3 Compute Firmware
Qualcomm Snapdragon 7c\+ Gen 3 Compute
Qualcomm Sm8450 Firmware
Qualcomm Sm8450
Qualcomm Sm8475 Firmware
Qualcomm Sm8475
Qualcomm Sm8150 Firmware
Qualcomm Sm8150
Qualcomm Sm8150-ac Firmware
Qualcomm Sm8150-ac
Qualcomm Sm8250 Firmware
Qualcomm SM8250
Qualcomm Sm8250-ab Firmware
Qualcomm Sm8250-ab
Qualcomm Sm8250-ac Firmware
Qualcomm Sm8250-ac
Qualcomm Snapdragon Auto 5g Modem-rf Firmware
Qualcomm Snapdragon Auto 5g Modem-rf
Qualcomm Snapdragon X50 5g Modem-rf System Firmware
Qualcomm Snapdragon X50 5g Modem-rf System
Qualcomm Snapdragon X55 5g Modem-rf System Firmware
Qualcomm Snapdragon X55 5g Modem-rf System
Qualcomm Snapdragon X65 5g Modem-rf System Firmware
Qualcomm Snapdragon X65 5g Modem-rf System
Qualcomm Snapdragon X70 Modem-rf System Firmware
Qualcomm Snapdragon X70 Modem-rf System
Qualcomm Snapdragon Xr2 5g Platform Firmware
Qualcomm Snapdragon Xr2 5g Platform
Qualcomm Sxr2130 Firmware
Qualcomm Sxr2130
Qualcomm Wcd9341 Firmware
Google Android
Google Android
Google Android
Qualcomm Wcd9370 Firmware
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Qualcomm Wcn6740
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android
Google Android

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-40508?

    The severity of CVE-2022-40508 is high with a severity value of 7.

  • Which software is affected by CVE-2022-40508?

    Google Android is affected by CVE-2022-40508.

  • What is the cause of CVE-2022-40508?

    The cause of CVE-2022-40508 is a transient DOS (Denial of Service) due to a reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.

  • How can I fix CVE-2022-40508?

    To fix CVE-2022-40508, it is recommended to update to the latest version of Google Android as soon as it becomes available.

  • Where can I find more information about CVE-2022-40508?

    You can find more information about CVE-2022-40508 in the following references: [Qualcomm Product Security Bulletins - May 2023](https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin), [Android Security Bulletin - May 2023](https://source.android.com/docs/security/bulletin/2023-05-01/#asterisk).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203