CVE-2022-33248Integer Overflow to Buffer Overflow in INC Snapdragon

Severity
7.8HIGHNVD
EPSS
0.1%
top 68.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 20

Description

Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon162 versions+161

🔴Vulnerability Details

1
GHSA
GHSA-qjhr-gq7c-8mxc: Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http2023-02-12

📋Vendor Advisories

1
Android
CVE-2022-33248: Closed-source component2023-02-01

📄Research Papers

1
arXiv
ChatNVD: Advancing Cybersecurity Vulnerability Assessment with Large Language Models2025-05-20