SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2022-22071

HIGH · CVSS 8.4 EPSS 0.45% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-14 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.4. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2023-12-05

Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE
CVE-2022-22071
Severity
HIGH
CVSS
8.4
EPSS
0.45%

Original NVD Description

Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

Related CVEs

Other vulnerabilities affecting the same vendor(s)