CVE-2025-22408
published 2025-08-26CVE-2025-22408: In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 15-next:0 < 15-next:2025-03-01 | 15-next:2025-03-01 |
| platform | packages_modules_bluetooth | >= 15:0 < 15:2025-03-01 | 15:2025-03-01 |
Android
CVE-2025-22408: Android Security Bulletin 2025-03-01
CVE: CVE-2025-22408
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 15
References: A-375397164
vendor_android·2025-03-01·CVSS 9.8
CVE-2025-22408 [CRITICAL] CVE-2025-22408: Android Security Bulletin 2025-03-01
CVE: CVE-2025-22408
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 15
References: A-375397164
Android Security Bulletin 2025-03-01
CVE: CVE-2025-22408
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 15
References: A-375397164
GHSA
GHSA-xj8c-32pp-9795: In rfc_check_send_cmd of rfc_utils
ghsa_unreviewed·2025-08-27
CVE-2025-22408 [CRITICAL] CWE-416 GHSA-xj8c-32pp-9795: In rfc_check_send_cmd of rfc_utils
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-22408: In rfc_check_send_cmd of rfc_utils
osv·2025-03-01
CVE-2025-22408 CVE-2025-22408: In rfc_check_send_cmd of rfc_utils
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-26
Published