In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420037; Issue ID: GN20220420037.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/August-2022 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
History
05 Aug 2022, 03:39
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-787 | |
First Time |
Mediatek mt7622 Firmware
Mediatek mt7613 Mediatek mt7610 Mediatek mt7620 Mediatek mt7613 Firmware Mediatek mt8981 Mediatek mt7629 Mediatek mt7916 Firmware Mediatek mt7603 Firmware Mediatek mt7916 Mediatek mt7612 Firmware Mediatek mt7612 Mediatek mt7915 Firmware Mediatek mt7615 Mediatek mt7915 Mediatek Mediatek mt7628 Firmware Mediatek mt7628 Mediatek mt7620 Firmware Mediatek mt7986 Mediatek mt7603 Mediatek mt7629 Firmware Mediatek mt7986 Firmware Mediatek mt7622 Mediatek mt7615 Firmware Mediatek mt7610 Firmware Mediatek mt8981 Firmware |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
CPE | cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7615_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7610:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7612_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7622_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7628_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7613_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7916_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7603_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7620_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7916:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt8981_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7629_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7986_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7915_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8981:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7986:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7612:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7610_firmware:7.6.2.3:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7603:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7620:-:*:*:*:*:*:*:* |
|
References | (MISC) https://corp.mediatek.com/product-security-bulletin/August-2022 - Vendor Advisory |
01 Aug 2022, 14:32
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-01 14:15
Updated : 2023-12-10 14:35
NVD link : CVE-2022-26440
Mitre link : CVE-2022-26440
CVE.ORG link : CVE-2022-26440
JSON object : View
Products Affected
mediatek
- mt7915_firmware
- mt7629
- mt7620
- mt7613_firmware
- mt7622
- mt7986
- mt8981
- mt7610
- mt7916_firmware
- mt7615_firmware
- mt7612
- mt7622_firmware
- mt7603
- mt7915
- mt7916
- mt7620_firmware
- mt7615
- mt7610_firmware
- mt7628_firmware
- mt7612_firmware
- mt7986_firmware
- mt8981_firmware
- mt7613
- mt7628
- mt7603_firmware
- mt7629_firmware
CWE
CWE-787
Out-of-bounds Write