In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/May-2022 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
12 May 2022, 02:08
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:mediatek:mt9636:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9255:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9666:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9630:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9011:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9685:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9215:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9688:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:4.19:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9629:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9288:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9652:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9220:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9613:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9602:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9269:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9639:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9216:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9670:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9610:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9600:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9221:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9686:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9638:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9256:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9285:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9631:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9286:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9615:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9632:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9675:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9650:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9612:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9617:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9611:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9669:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:4.9:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt9266:-:*:*:*:*:*:*:* |
|
References | (MISC) https://corp.mediatek.com/product-security-bulletin/May-2022 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 6.7 |
CWE | CWE-787 | |
First Time |
Mediatek mt9688
Mediatek mt9615 Linux linux Kernel Mediatek mt9216 Mediatek mt9670 Mediatek mt9632 Mediatek mt9255 Mediatek mt9288 Mediatek mt9600 Mediatek mt9611 Mediatek mt9285 Mediatek Mediatek mt9610 Mediatek mt9617 Mediatek mt9685 Mediatek mt9666 Mediatek mt9669 Mediatek mt9650 Mediatek mt9613 Mediatek mt9686 Mediatek mt9220 Mediatek mt9638 Mediatek mt9286 Mediatek mt9011 Mediatek mt9675 Mediatek mt9639 Mediatek mt9221 Mediatek mt9636 Mediatek mt9266 Mediatek mt9631 Google android Mediatek mt9602 Mediatek mt9269 Mediatek mt9652 Linux Mediatek mt9629 Mediatek mt9256 Mediatek mt9630 Mediatek mt9612 Mediatek mt9215 |
03 May 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-05-03 21:15
Updated : 2023-12-10 14:22
NVD link : CVE-2022-20106
Mitre link : CVE-2022-20106
CVE.ORG link : CVE-2022-20106
JSON object : View
Products Affected
mediatek
- mt9669
- mt9255
- mt9650
- mt9610
- mt9602
- mt9611
- mt9615
- mt9666
- mt9630
- mt9629
- mt9285
- mt9632
- mt9256
- mt9639
- mt9675
- mt9266
- mt9652
- mt9216
- mt9288
- mt9011
- mt9636
- mt9600
- mt9215
- mt9221
- mt9617
- mt9670
- mt9688
- mt9269
- mt9631
- mt9686
- mt9685
- mt9220
- mt9638
- mt9286
- mt9612
- mt9613
linux
- linux_kernel
- android
CWE
CWE-787
Out-of-bounds Write