CVE-2022-40515Double Free in INC Snapdragon

CWE-415Double Free3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
0.2%
top 61.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10

Description

Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon159 versions+158

🔴Vulnerability Details

1
GHSA
GHSA-g5q2-299m-wxw3: Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms2023-03-10

📋Vendor Advisories

1
Android
CVE-2022-40515: Closed-source component2023-03-01