CVE-2022-22086
HIGHSnapdragon Auto - Memory Corruption
Title source: llmDescription
Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Scores
CVSS v3
7.3
EPSS
0.0028
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-415
Status
published
Affected Products (50)
qualcomm/apq8009w_firmware
qualcomm/apq8017_firmware
qualcomm/apq8053_firmware
qualcomm/apq8096au_firmware
qualcomm/aqt1000_firmware
qualcomm/ar8031_firmware
qualcomm/csra6620_firmware
qualcomm/csra6640_firmware
qualcomm/mdm9206_firmware
qualcomm/mdm9650_firmware
qualcomm/msm8909w_firmware
qualcomm/msm8917_firmware
qualcomm/msm8953_firmware
qualcomm/msm8996au_firmware
qualcomm/qca6174a_firmware
... and 35 more
Timeline
Published
Jun 14, 2022
Tracked Since
Feb 18, 2026