Lucene search

K
cve[email protected]CVE-2022-40540
HistoryMar 10, 2023 - 9:15 p.m.

CVE-2022-40540

2023-03-1021:15:12
CWE-120
web.nvd.nist.gov
58
cve-2022-40540
memory corruption
firmware loading
linux kernel
nvd

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel.

Affected configurations

NVD
Node
qualcommsm8475Match-
AND
qualcommsd_8_gen1_5g_firmwareMatch-
Node
qualcommsd888_5gMatch-
AND
qualcommsd888_5g_firmwareMatch-
Node
qualcommsw5100Match-
AND
qualcommsw5100_firmwareMatch-
Node
qualcommsw5100pMatch-
AND
qualcommsw5100p_firmwareMatch-
Node
qualcommwcd9380Match-
AND
qualcommwcd9380_firmwareMatch-
Node
qualcommwcd9385Match-
AND
qualcommwcd9385_firmwareMatch-
Node
qualcommwcn3980Match-
AND
qualcommwcn3980_firmwareMatch-
Node
qualcommwcn3988Match-
AND
qualcommwcn3988_firmwareMatch-
Node
qualcommwcn6850Match-
AND
qualcommwcn6850_firmwareMatch-
Node
qualcommwcn6851Match-
AND
qualcommwcn6851_firmwareMatch-
Node
qualcommwcn6855Match-
AND
qualcommwcn6855_firmwareMatch-
Node
qualcommwcn6856Match-
AND
qualcommwcn6856_firmwareMatch-
Node
qualcommwcn7850Match-
AND
qualcommwcn7850_firmwareMatch-
Node
qualcommwcn7851Match-
AND
qualcommwcn7851_firmwareMatch-
Node
qualcommwsa8830Match-
AND
qualcommwsa8830_firmwareMatch-
Node
qualcommwsa8835Match-
AND
qualcommwsa8835_firmwareMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Snapdragon Mobile",
      "Snapdragon Wearables"
    ],
    "product": "Snapdragon",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "SD 8 Gen1 5G"
      },
      {
        "status": "affected",
        "version": "SD888 5G"
      },
      {
        "status": "affected",
        "version": "SW5100"
      },
      {
        "status": "affected",
        "version": "SW5100P"
      },
      {
        "status": "affected",
        "version": "WCD9380"
      },
      {
        "status": "affected",
        "version": "WCD9385"
      },
      {
        "status": "affected",
        "version": "WCN3980"
      },
      {
        "status": "affected",
        "version": "WCN3988"
      },
      {
        "status": "affected",
        "version": "WCN6850"
      },
      {
        "status": "affected",
        "version": "WCN6851"
      },
      {
        "status": "affected",
        "version": "WCN6855"
      },
      {
        "status": "affected",
        "version": "WCN6856"
      },
      {
        "status": "affected",
        "version": "WCN7850"
      },
      {
        "status": "affected",
        "version": "WCN7851"
      },
      {
        "status": "affected",
        "version": "WSA8830"
      },
      {
        "status": "affected",
        "version": "WSA8835"
      }
    ]
  }
]

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2022-40540