CVE-2022-33288Classic Buffer Overflow in INC Snapdragon

Severity
8.8HIGHNVD
EPSS
0.1%
top 78.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13

Description

Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon126 versions+125

🔴Vulnerability Details

1
GHSA
GHSA-fwgv-m2q7-ffhf: Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information2023-04-13

📋Vendor Advisories

1
Android
CVE-2022-33288: Closed-source component2023-04-01