CVE-2022-25654

Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:apq8096au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8096au:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:mdm9650:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6174a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:qcs603_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs603:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs605:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:qualcomm215_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qualcomm215:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:sd429_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd429:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:sd820_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd820:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:sdm429w_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdm429w:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:wcd9326_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9326:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:qualcomm:wcd9335_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9335:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9341:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:qualcomm:wcn3615_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3615:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:qualcomm:wcn3620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3620:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3660b:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:qualcomm:wcn3680_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3680:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:qualcomm:wcn3990_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3990:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-20 CWE-787

20 Sep 2022, 13:21

Type Values Removed Values Added
First Time Qualcomm apq8096au
Qualcomm wcn3680 Firmware
Qualcomm sd820 Firmware
Qualcomm qcs605
Qualcomm sdm429w Firmware
Qualcomm wcn3660b
Qualcomm qcs605 Firmware
Qualcomm wsa8810
Qualcomm qca6174a Firmware
Qualcomm wcn3980
Qualcomm wcd9341 Firmware
Qualcomm wcn3615 Firmware
Qualcomm sd429
Qualcomm wcn3990 Firmware
Qualcomm
Qualcomm sd820
Qualcomm qca6574au
Qualcomm wsa8810 Firmware
Qualcomm qca6174a
Qualcomm apq8096au Firmware
Qualcomm wcn3990
Qualcomm wcd9326 Firmware
Qualcomm wcd9335
Qualcomm mdm9650 Firmware
Qualcomm sd429 Firmware
Qualcomm qca6574au Firmware
Qualcomm wcd9326
Qualcomm wcn3680
Qualcomm wcn3615
Qualcomm mdm9650
Qualcomm wcn3660b Firmware
Qualcomm wcd9341
Qualcomm wcd9335 Firmware
Qualcomm wcn3620
Qualcomm wcn3980 Firmware
Qualcomm wsa8815 Firmware
Qualcomm qcs603 Firmware
Qualcomm wsa8815
Qualcomm sdm429w
Qualcomm qualcomm215 Firmware
Qualcomm qcs603
Qualcomm qualcomm215
Qualcomm wcn3620 Firmware
CPE cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd429:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:apq8096au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs605:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3990_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9335:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd820:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd429_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3615:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:mdm9650:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdm429w:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sdm429w_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9341:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3660b:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3620:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qualcomm215_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qualcomm215:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs603:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8096au:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd820_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3615_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3980:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3990:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9326:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3680:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9326_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcs603_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3680_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9335_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6174a:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:*
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7
References (CONFIRM) https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin - (CONFIRM) https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin - Patch, Vendor Advisory

16 Sep 2022, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-16 06:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-25654

Mitre link : CVE-2022-25654

CVE.ORG link : CVE-2022-25654


JSON object : View

Products Affected

qualcomm

  • sd820_firmware
  • wcn3980
  • wcn3990
  • wcn3990_firmware
  • wcn3660b
  • wsa8815_firmware
  • wcn3980_firmware
  • wcn3660b_firmware
  • qualcomm215_firmware
  • apq8096au
  • qca6574au
  • sdm429w_firmware
  • qualcomm215
  • wcd9326_firmware
  • wcn3615
  • qcs605
  • wcd9335
  • wcn3680
  • wsa8810_firmware
  • sd820
  • qca6574au_firmware
  • wcn3680_firmware
  • wcn3620_firmware
  • mdm9650
  • mdm9650_firmware
  • sdm429w
  • apq8096au_firmware
  • wcn3620
  • qca6174a_firmware
  • wcd9341_firmware
  • wcd9341
  • wsa8815
  • wcd9326
  • wcd9335_firmware
  • qca6174a
  • wcn3615_firmware
  • qcs603_firmware
  • qcs605_firmware
  • wsa8810
  • sd429_firmware
  • qcs603
  • sd429
CWE
CWE-787

Out-of-bounds Write