HIGH
CVE-2022-22265
CVSS
7.8
KEV
Description
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
Summary dbcve.org
This vulnerability exists in the NPU (Neural Processing Unit) driver code prior to the SMR Jan-2022 Release 1 update. The driver improperly handles exceptional conditions, allowing an attacker to achieve arbitrary memory write operations and ultimately execute arbitrary code. This is a local privilege escalation vulnerability in the device driver layer.
Mitigation
Apply the SMR Jan-2022 Release 1 or later security patch, which contains the corrected NPU driver with proper exceptional condition handling. For affected devices, update the firmware/NA kernel to the patched version.
Weakness (CWE)
CWE-703
EPSS Score
0.39%
Probability of exploitation in next 30 days
30.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.