LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22071: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 5, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 26, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22071 to its Known Exploited Vulnerabilities catalog on Dec 5, 2023, with a federal patch deadline of Dec 26, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.

CVE-2022-22071 is a use-after-free vulnerability in multiple Qualcomm chipsets. According to the CISA summary, it occurs when process shell memory is freed using an IOCTL munmap call while process initialization is still in progress.

This class of flaw matters to IT and security teams because Qualcomm chipsets power a wide range of mobile, embedded, and connected devices. A successful abuse of use-after-free conditions can lead to memory corruption that may enable further compromise of the device. Exact impact depends on the specific product and environment; confirm details against the vendor advisory.

How it works

The weakness is CWE-416 (Use After Free). In this case, the vulnerability is triggered when process shell memory is freed via an IOCTL munmap call at the same time process initialization is underway.

An attacker who can influence the timing or sequence of these memory operations may cause the system to reference memory that has already been freed. This can produce undefined behavior such as crashes or, in some circumstances, memory corruption that an attacker might try to leverage. No specific exploit mechanics, payloads, or prerequisites beyond the CISA description are provided here; treat any deeper technical claims as requiring confirmation against the vendor advisory.

Am I affected? How to find it in your systems

Qualcomm chipsets appear in smartphones, tablets, IoT devices, automotive systems, and other hardware. Public detail is limited to “multiple chipsets,” so inventory must be driven by vendor data rather than a fixed version list.

Because exact version ranges are not given in the available facts, always confirm affected status and any detection guidance directly with the vendor advisory.

How to remediate

CISA’s required action is to apply remediations or mitigations per vendor instructions, or to discontinue use of the product if remediation or mitigations are unavailable.

For this weakness class, also apply general hardening: keep related drivers and firmware current, enforce least privilege on processes that interact with the chipset, and restrict unnecessary IOCTL access where the platform allows it.

If you can't patch immediately

Until a vendor fix can be applied, reduce exposure with compensating controls appropriate to a use-after-free condition in chipset firmware or drivers.

These measures lower risk but do not eliminate the underlying vulnerability; plan to apply the official remediation as soon as it is available.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure. Ransomware use of this CVE is not documented. If you believe systems containing the affected Qualcomm chipsets may have been targeted, follow your incident-response process, preserve relevant logs, and assess whether sensitive data could have been accessed. As a general hygiene step, you can run a free exposure scan of your email address to check whether it appears in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQualcomm · Multiple Chipsets
WeaknessCWE-416
Added to CISA KEVDec 5, 2023
Federal patch deadlineDec 26, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities