CVE-2022-33280Access of Uninitialized Pointer in INC Snapdragon

Severity
8.8HIGHNVD
EPSS
0.3%
top 46.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12

Description

Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon62 versions+61

Patches

🔴Vulnerability Details

1
GHSA
GHSA-278x-ph66-x5gw: Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet2023-02-12

📋Vendor Advisories

1
Android
CVE-2022-33280: Bluetooth2023-02-01