← Vulnerability feed

Vulnerability record · CVE-2022-22071 · published 14 June 2022

CVE-2022-22071: Qualcomm chipset shell memory use-after-free via IOCTL munmap

Qualcomm · Apq8053 Firmware

A use-after-free exists in Qualcomm Snapdragon and related chipset firmware when process shell memory is freed through an IOCTL munmap call while process initialization is still in progress. The flaw is rated CVSS 3.1 7.8 (HIGH) and affects a broad set of Qualcomm firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, and Voice & Music lines. It matters because memory corruption in a privileged component can lead to code execution or full compromise of the affected device.

7.8 CVSS 3.1 High CISA KEV since 5 Dec 2023 EPSS 0.46% · top 63.0% CWE-416 · Use after free
7.8CVSS 3.1 base score, v2 7.2
0.46%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
90Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCVSS 7.8 with high confidentiality, integrity, and availability impact plus CISA KEV listing indicates active exploitation, though the local vector and low EPSS temper the urgency relative to remotely exploitable flaws.

What it is

A use-after-free exists in Qualcomm Snapdragon and related chipset firmware when process shell memory is freed through an IOCTL munmap call while process initialization is still in progress. The flaw is rated CVSS 3.1 7.8 (HIGH) and affects a broad set of Qualcomm firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, and Voice & Music lines. It matters because memory corruption in a privileged component can lead to code execution or full compromise of the affected device.

Impact

An attacker who can trigger the race gains high confidentiality, integrity, and availability impact, potentially executing code in the context of the affected process. Because the vector is local with low privileges, the practical gain is privilege escalation or persistent control on the device.

Attack surface

The vector is AV:L/AC:L/PR:L/UI:N, so the flaw is reached locally by an attacker who already has low-privileged access to the device; no user interaction is required. It is not remotely reachable per the supplied CVSS vector.

Exploitation

CVE-2022-22071 is listed in CISA KEV (added 2023-12-05, due 2023-12-26), indicating known exploitation in the wild, while EPSS is low at 0.00455 (38.6th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Qualcomm May 2022 security bulletin patches for all affected chipsets; treat this as the primary action.
  • If patching is not immediately possible, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
  • Restrict local access and limit low-privileged code execution paths on affected devices to reduce the attack surface.
  • Track affected firmware inventory against the Qualcomm product list and prioritize devices exposed to untrusted local users.

Detection

  • Monitor for abnormal IOCTL munmap activity or crashes in processes handling shell memory during initialization.
  • Watch for use-after-free indicators such as memory corruption crashes, unexpected process termination, or kernel/process fault logs on affected Qualcomm devices.
  • Correlate local privilege escalation attempts or anomalous process behavior on devices running unpatched Qualcomm firmware.
  • Use firmware version inventory to identify unpatched devices and flag them for remediation tracking.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22071 to the Known Exploited Vulnerabilities catalog on 5 December 2023 as "Qualcomm Multiple Chipsets Use-After-Free Vulnerability". Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 26 December 2023.

Affected products

90 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22071 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-21385Qualcomm chipset firmware memory corruption via alignment integer overflowA memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It af…KEVEPSS 1.2%analysed7.8CVE-2023-33107Qualcomm Graphics Linux integer overflow memory corruptionCVE-2023-33107 is an integer overflow (CWE-190) in Qualcomm Graphics Linux that causes memory corruption when a shared virtual memory region is assig…KEVEPSS 0.89%analysed7.8CVE-2023-33106Qualcomm GPU AUX Command Sync Point Memory CorruptionCVE-2023-33106 is a memory corruption flaw in Qualcomm chipsets triggered when a large list of sync points is submitted in an AUX command to the IOCT…KEVEPSS 0.92%analysed7.8CVE-2023-33063Qualcomm DSP Services use-after-free memory corruptionCVE-2023-33063 is a use-after-free memory corruption flaw in Qualcomm DSP Services, triggered during a remote call from the high-level operating syst…KEVEPSS 0.69%analysed7.8CVE-2020-11261Qualcomm Snapdragon chipsets memory corruption via improper allocation size checkQualcomm Snapdragon firmware fails to return an error when a user application requests a very large memory allocation, leading to memory corruption (…KEVEPSS 1.6%analysed7.8CVE-2021-1905Qualcomm Snapdragon chipsets use-after-free in memory mapping handlingA use-after-free flaw exists in multiple Qualcomm Snapdragon chipset families due to improper handling of memory mapping when multiple processes oper…KEVEPSS 1.5%analysed7.5CVE-2025-27038Qualcomm Adreno GPU driver use-after-free in Chrome graphics renderingA use-after-free (CWE-416) in Qualcomm Adreno GPU drivers causes memory corruption while rendering graphics in Chrome. It affects a broad set of Qual…KEVEPSS 1.0%analysed5.5CVE-2021-1906Qualcomm Snapdragon GPU address deregistration failure causes allocation denialImproper handling of address deregistration on failure in Qualcomm Snapdragon chipsets can cause subsequent GPU address allocation to fail. The flaw …KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2022-22071), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.