Vulnerability record · CVE-2022-22071 · published 14 June 2022
CVE-2022-22071: Qualcomm chipset shell memory use-after-free via IOCTL munmap
Qualcomm · Apq8053 Firmware
A use-after-free exists in Qualcomm Snapdragon and related chipset firmware when process shell memory is freed through an IOCTL munmap call while process initialization is still in progress. The flaw is rated CVSS 3.1 7.8 (HIGH) and affects a broad set of Qualcomm firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, and Voice & Music lines. It matters because memory corruption in a privileged component can lead to code execution or full compromise of the affected device.
Description
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity, and availability impact plus CISA KEV listing indicates active exploitation, though the local vector and low EPSS temper the urgency relative to remotely exploitable flaws.
What it is
A use-after-free exists in Qualcomm Snapdragon and related chipset firmware when process shell memory is freed through an IOCTL munmap call while process initialization is still in progress. The flaw is rated CVSS 3.1 7.8 (HIGH) and affects a broad set of Qualcomm firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, and Voice & Music lines. It matters because memory corruption in a privileged component can lead to code execution or full compromise of the affected device.
Impact
An attacker who can trigger the race gains high confidentiality, integrity, and availability impact, potentially executing code in the context of the affected process. Because the vector is local with low privileges, the practical gain is privilege escalation or persistent control on the device.
Attack surface
The vector is AV:L/AC:L/PR:L/UI:N, so the flaw is reached locally by an attacker who already has low-privileged access to the device; no user interaction is required. It is not remotely reachable per the supplied CVSS vector.
Exploitation
CVE-2022-22071 is listed in CISA KEV (added 2023-12-05, due 2023-12-26), indicating known exploitation in the wild, while EPSS is low at 0.00455 (38.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the Qualcomm May 2022 security bulletin patches for all affected chipsets; treat this as the primary action.
- If patching is not immediately possible, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
- Restrict local access and limit low-privileged code execution paths on affected devices to reduce the attack surface.
- Track affected firmware inventory against the Qualcomm product list and prioritize devices exposed to untrusted local users.
Detection
- Monitor for abnormal IOCTL munmap activity or crashes in processes handling shell memory during initialization.
- Watch for use-after-free indicators such as memory corruption crashes, unexpected process termination, or kernel/process fault logs on affected Qualcomm devices.
- Correlate local privilege escalation attempts or anomalous process behavior on devices running unpatched Qualcomm firmware.
- Use firmware version inventory to identify unpatched devices and flag them for remediation tracking.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22071 to the Known Exploited Vulnerabilities catalog on 5 December 2023 as "Qualcomm Multiple Chipsets Use-After-Free Vulnerability". Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 26 December 2023.
Affected products
90 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qualcomm.com/company/product-security/bulletins/may-2022-bulletin | PatchVendor Advisory |
| https://www.qualcomm.com/company/product-security/bulletins/may-2022-bulletin | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22071 | US Government Resource |
Track CVE-2022-22071 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22071), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.