CVE-2022-22265 Details
Description
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
A use-after-free vulnerability has been identified in the NPU driver of Samsung mobile devices with selected Exynos chipsets, prior to the January 2022 Security Maintenance Release. This vulnerability arises from improper handling of exceptional conditions, allowing arbitrary memory writes and code execution.
Users can apply the January 2022 Security Maintenance Release, which includes the necessary patch for this vulnerability. Instructions for updating can be found on the Samsung Mobile Security website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 15, 2023References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22265 | CISA-ADP | US Government Resource |
| https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=1 | CVE | Vendor Advisory |
| https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=1 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Samsung Mobile Devices Use-After-Free Vulnerability | Sep 18, 2023 | Oct 9, 2023 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-703 | Improper Check or Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google android | 9.0 10.0 11.0 12.0 |
CPE
Remediation
| |
| samsung exynos | All versions |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jun 27, 2023 | Reanalysis | [email protected] |
| Jan 14, 2022 | Initial Analysis | [email protected] |