PT-2022-4766 · Qualcomm · Snapdragon Mobile+8
Published
2022-06-06
·
Updated
2023-08-08
·
CVE-2022-22074
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Qualcomm embedded platform software (affected versions not specified)
Snapdragon Auto (affected versions not specified)
Snapdragon Compute (affected versions not specified)
Snapdragon Connectivity (affected versions not specified)
Snapdragon Consumer IOT (affected versions not specified)
Snapdragon Industrial IOT (affected versions not specified)
Snapdragon Mobile (affected versions not specified)
Snapdragon Voice & Music (affected versions not specified)
Snapdragon Wearables (affected versions not specified)
Description
The issue is related to an integer overflow in the Audio component of Qualcomm's microprogrammed software for embedded platforms when playing wma files. This can lead to memory corruption. Exploitation of the issue may allow an attacker to cause a denial of service or execute arbitrary code.
Recommendations
For Qualcomm embedded platform software, update to a version that fixes the integer overflow issue in the Audio component.
For Snapdragon Auto, restrict access to wma file playback until a patch is available.
For Snapdragon Compute, consider disabling the
wma file playback functionality until a fix is released.
For Snapdragon Connectivity, avoid using the vulnerable Audio component until an update is provided.
For Snapdragon Consumer IOT, restrict the use of wma file playback to minimize the risk of exploitation.
For Snapdragon Industrial IOT, update the software to a version that addresses the integer overflow issue.
For Snapdragon Mobile, apply configuration changes to prevent the exploitation of the vulnerable Audio component.
For Snapdragon Voice & Music, temporarily disable the wma file playback feature until a patch is available.
For Snapdragon Wearables, update the software to a version that fixes the memory corruption issue.Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qualcomm Embedded Platform
Snapdragon Auto
Snapdragon Compute
Snapdragon Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Voice & Music
Snapdragon Wearables