ZeroHour

CVE-2022-22071

KEVmass

Exploited Use-After-Free in Qualcomm Snapdragon and QCA Chipset Firmware

CISA: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
<1%p38
Published
()
KEV added
AI analysis

CVE-2022-22071 is a use-after-free (CWE-416) in the firmware of multiple Qualcomm Snapdragon SoCs and QCA connectivity chips, occurring when process shell memory is freed via an IOCTL munmap call while process initialization is still in progress. It is triggered locally by a low-privileged process during this initialization/memory-free sequence, so an attacker who can already run code on the device can exploit it. The result is high-impact memory corruption affecting confidentiality, integrity, and availability (CVSS 3.1: 7.8), consistent with local privilege escalation or full compromise of the affected chipset-based system. Any device built on the listed Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, or Voice & Music platforms is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-05, news reports describe Qualcomm patching three actively exploited zero-days in this disclosure, and ransomware use is unknown; EPSS is 0.5% and no public PoC is known.

What to do: Apply the firmware fixes published in Qualcomm's security advisory via your device OEM or OS update channel, following CISA's KEV required action (patch per vendor instructions or discontinue use). Inventory devices using the listed chipsets (MSM8953/APQ8053, AR8031/AR8035, CSRA6620/CSRA6640, MDM9150, QCA6174A/6390/6391/6426/6436) and prioritize those where untrusted or low-privileged users can run code locally. Because the flaw is local-only, mitigate interim risk by restricting local code execution on affected devices; no public PoC or specific patched firmware version is available in the source data.

Affected
Qualcomm APQ8053 firmware
Qualcomm AR8031 firmware
Qualcomm AR8035 firmware
Qualcomm CSRA6620 firmware
Qualcomm CSRA6640 firmware
Qualcomm MDM9150 firmware
Qualcomm MSM8953 firmware
Qualcomm QCA6174A firmware
Qualcomm QCA6390 firmware
Qualcomm QCA6391 firmware
Qualcomm QCA6426 firmware
Qualcomm QCA6436 firmware
Estimated exposure
massHundreds of millions of devices plausibly affected (chipsets deployed across smartphone, IoT, automotive, and embedded product lines) — The affected SoCs and Wi-Fi/Bluetooth chips (e.g., MSM8953/APQ8053 and the QCA6xxx family) ship inside devices from many OEMs across multiple markets, so the plausible exposure floor is well above 1M devices, though exact install counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

CISA Known Exploited Vulnerability
Affected
Qualcomm Multiple Chipsets
Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
qualcomm
Products
apq8053 firmware, ar8031 firmware, ar8035 firmware, csra6620 firmware, csra6640 firmware, mdm9150 firmware, msm8953 firmware, qca6174a firmware, qca6390 firmware, qca6391 firmware, qca6426 firmware, qca6436 firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news