CVE-2022-22071
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto,...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 21, 2021
- Published Date
- June 14, 2022
- Last Updated
- February 04, 2025
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- Description
- Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- Tags
- Exploitation
- active
- Technical Impact
- total
- Exploited in the Wild
- Yes (2023-12-05 00:00:00 UTC) Source
cisa
CVSS Scores
CVSS v3.1
8.4 - HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
Exploit Status
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-12-05 00:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel