CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.4. It affects Linux, Android. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild.
CISA KEV Details
Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Ransomware use: Unknown
Added to KEV: 2022-09-15
Required action: Apply updates per vendor instructions.
Original NVD Description
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.