CVE-2022-25654

MEDIUM

Qualcomm Firmware - Memory Corruption via ION Command Processing

Title source: llm
STIX 2.1

Description

Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0011
EPSS Percentile 28.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (21)
qualcomm/apq8096au_firmware
qualcomm/mdm9650_firmware
qualcomm/qca6174a_firmware
qualcomm/qca6574au_firmware
qualcomm/qcs603_firmware
qualcomm/qcs605_firmware
qualcomm/qualcomm215_firmware
qualcomm/sd429_firmware
qualcomm/sd820_firmware
qualcomm/sdm429w_firmware
... and 11 more
Published Sep 16, 2022
Tracked Since Feb 18, 2026