CVE-2022-22265

5.0MEDIUM

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

Publicado: 1/10/2022Actualizado: 10/30/2025

Vulnerabilidad Explotada Conocida (CISA)

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.

Acción Requerida:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Fecha Límite:

2023-10-09

Descripción

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

Análisis IAImpulsado por IA

Productos Afectados

googleandroid
9.0
googleandroid
10.0
googleandroid
11.0
googleandroid
12.0
samsungexynos
-

Referencias