CVE-2022-22071
KEVmassExploited Use-After-Free in Qualcomm Snapdragon and QCA Chipset Firmware
CISA: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
CVE-2022-22071 is a use-after-free (CWE-416) in the firmware of multiple Qualcomm Snapdragon SoCs and QCA connectivity chips, occurring when process shell memory is freed via an IOCTL munmap call while process initialization is still in progress. It is triggered locally by a low-privileged process during this initialization/memory-free sequence, so an attacker who can already run code on the device can exploit it. The result is high-impact memory corruption affecting confidentiality, integrity, and availability (CVSS 3.1: 7.8), consistent with local privilege escalation or full compromise of the affected chipset-based system. Any device built on the listed Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, or Voice & Music platforms is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-05, news reports describe Qualcomm patching three actively exploited zero-days in this disclosure, and ransomware use is unknown; EPSS is 0.5% and no public PoC is known.
What to do: Apply the firmware fixes published in Qualcomm's security advisory via your device OEM or OS update channel, following CISA's KEV required action (patch per vendor instructions or discontinue use). Inventory devices using the listed chipsets (MSM8953/APQ8053, AR8031/AR8035, CSRA6620/CSRA6640, MDM9150, QCA6174A/6390/6391/6426/6436) and prioritize those where untrusted or low-privileged users can run code locally. Because the flaw is local-only, mitigate interim risk by restricting local code execution on affected devices; no public PoC or specific patched firmware version is available in the source data.
| Qualcomm APQ8053 firmware | — |
| Qualcomm AR8031 firmware | — |
| Qualcomm AR8035 firmware | — |
| Qualcomm CSRA6620 firmware | — |
| Qualcomm CSRA6640 firmware | — |
| Qualcomm MDM9150 firmware | — |
| Qualcomm MSM8953 firmware | — |
| Qualcomm QCA6174A firmware | — |
| Qualcomm QCA6390 firmware | — |
| Qualcomm QCA6391 firmware | — |
| Qualcomm QCA6426 firmware | — |
| Qualcomm QCA6436 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- apq8053 firmware, ar8031 firmware, ar8035 firmware, csra6620 firmware, csra6640 firmware, mdm9150 firmware, msm8953 firmware, qca6174a firmware, qca6390 firmware, qca6391 firmware, qca6426 firmware, qca6436 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H