PT-2022-4883 · Qualcomm · Qualcomm Snapdragon

Lei Ai

+1

·

Published

2022-03-17

·

Updated

2023-04-19

·

CVE-2022-25706

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:P
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon versions (affected versions not specified)
Description The issue is related to a buffer over-read in the Bluetooth driver while reading l2cap length, potentially allowing an unauthorized access to protected information or causing a denial of service. This is due to the lack of buffer length checks and out-of-bounds memory reading when handling the l2cap parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Over-read

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2022-06022
CVE-2022-25706

Affected Products

Qualcomm Snapdragon