ID

VAR-202210-1446


CVE

CVE-2022-25750


TITLE

Double release vulnerability in multiple Qualcomm products

Trust: 0.8

sources: JVNDB: JVNDB-2022-019492

DESCRIPTION

Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile. kailua firmware, sg8275 firmware, sg8275p Multiple Qualcomm products, including firmware, contain a double release vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2022-25750 // JVNDB: JVNDB-2022-019492

IOT TAXONOMY

category:['other device', 'embedded device']sub_category:SoC

Trust: 0.1

category:['other device', 'embedded device']sub_category:general

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:qualcommmodel:wcn6856scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn7851scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wsa8840scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9395scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sm8550scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wsa8845scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:kailuascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9390scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9385scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn6855scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wsa8845hscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9380scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn7850scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sg8275scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sg8275pscope:eqversion: -

Trust: 1.0

vendor:クアルコムmodel:wcd9390scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wcd9380scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:sg8275scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wsa8845hscope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wcn7850scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wcn6856scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:kailuascope: - version: -

Trust: 0.8

vendor:クアルコムmodel:sg8275pscope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wcd9385scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wsa8840scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wsa8845scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wcn7851scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:sm8550scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wcn6855scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:wcd9395scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-019492 // NVD: CVE-2022-25750

CVSS

SEVERITY

CVSSV2

CVSSV3

product-security@qualcomm.com: CVE-2022-25750
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2022-25750
value: HIGH

Trust: 1.0

NVD: CVE-2022-25750
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202210-1337
value: HIGH

Trust: 0.6

product-security@qualcomm.com: CVE-2022-25750
baseSeverity: HIGH
baseScore: 8.4
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.5
impactScore: 5.9
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2022-25750
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-25750
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-019492 // CNNVD: CNNVD-202210-1337 // NVD: CVE-2022-25750 // NVD: CVE-2022-25750

PROBLEMTYPE DATA

problemtype:CWE-415

Trust: 1.0

problemtype:Double release (CWE-415) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-019492 // NVD: CVE-2022-25750

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202210-1337

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-202210-1337

PATCH

title:Qualcomm BTHOST Remediation of resource management error vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=211514

Trust: 0.6

sources: CNNVD: CNNVD-202210-1337

EXTERNAL IDS

db:NVDid:CVE-2022-25750

Trust: 3.3

db:JVNDBid:JVNDB-2022-019492

Trust: 0.8

db:CNNVDid:CNNVD-202210-1337

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2022-019492 // CNNVD: CNNVD-202210-1337 // NVD: CVE-2022-25750

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins/october-2022-bulletin

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2022-25750

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-25750/

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2022-019492 // CNNVD: CNNVD-202210-1337 // NVD: CVE-2022-25750

SOURCES

db:OTHERid: -
db:JVNDBid:JVNDB-2022-019492
db:CNNVDid:CNNVD-202210-1337
db:NVDid:CVE-2022-25750

LAST UPDATE DATE

2025-05-14T20:53:27.922000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2022-019492date:2023-10-25T08:15:00
db:CNNVDid:CNNVD-202210-1337date:2022-10-21T00:00:00
db:NVDid:CVE-2022-25750date:2025-05-13T20:15:20.920

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2022-019492date:2023-10-25T00:00:00
db:CNNVDid:CNNVD-202210-1337date:2022-10-19T00:00:00
db:NVDid:CVE-2022-25750date:2022-10-19T11:15:10.953