CVE-2022-22265

5.0MEDIUM

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

Published: 1/10/2022Updated: 10/30/2025

CISA Known Exploited Vulnerability

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date:

2023-10-09

Description

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

AI AnalysisPowered by AI

Affected Products

googleandroid
9.0
googleandroid
10.0
googleandroid
11.0
googleandroid
12.0
samsungexynos
-

References