CVE-2022-20044: Use After Free
Published Feb 9, 2022
·Updated
In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID: ALPS06126814.
Affected Software
11 affected components
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android=12.0
MediaTek Mt8167
MediaTek Mt8175
MediaTek Mt8183
MediaTek Mt8362a
MediaTek Mt8365
MediaTek Mt8385
Event History
Feb 9, 2022
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-20044?
CVE-2022-20044 has a severity rating that indicates it could result in a local escalation of privilege due to a service crash.
2
How do I fix CVE-2022-20044?
To fix CVE-2022-20044, apply the patch identified with Patch ID: ALPS06126814.
3
Which versions of Android are affected by CVE-2022-20044?
CVE-2022-20044 affects Google Android versions 8.1 through 12.0.
4
Does CVE-2022-20044 require user interaction for exploitation?
No, CVE-2022-20044 does not require user interaction to be exploited.
5
Is there any affected hardware related to CVE-2022-20044?
CVE-2022-20044 primarily affects software; the listed MediaTek hardware configurations are not vulnerable.