CVE-2022-26439: Medium severity mediatek mt7603 firmware vulnerability
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420020; Issue ID: GN20220420020.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26439?
CVE-2022-26439 is a vulnerability in the wifi driver that allows for a possible out-of-bounds write due to a missing bounds check.
What is the severity of CVE-2022-26439?
The severity of CVE-2022-26439 is medium with a severity value of 6.7.
How can CVE-2022-26439 be exploited?
CVE-2022-26439 can be exploited locally without user interaction, leading to local escalation of privilege with system execution privileges required.
Which software versions are affected by CVE-2022-26439?
The Mediatek Mt7603 Firmware version 7.6.2.3 is affected by CVE-2022-26439.
Is there a patch available for CVE-2022-26439?
Yes, a patch with ID GN20220420020 is available for CVE-2022-26439. Refer to the Mediatek Product Security Bulletin for more information.