CVE-2022-26440: Medium severity mediatek mt7603 firmware vulnerability
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420037; Issue ID: GN20220420037.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26440?
CVE-2022-26440 is a vulnerability in the wifi driver that could lead to local escalation of privilege.
What software is affected by CVE-2022-26440?
The Mediatek Mt7603, Mt7610, Mt7612, Mt7613, Mt7615, Mt7620, Mt7622, Mt7628, Mt7629, Mt7915, Mt7916, Mt7986, and Mt8981 firmware are affected by CVE-2022-26440.
Is user interaction required for exploitation of CVE-2022-26440?
No, user interaction is not needed for exploitation of CVE-2022-26440.
What is the severity of CVE-2022-26440?
The severity of CVE-2022-26440 is medium with a CVSS score of 6.7.
How do I patch CVE-2022-26440?
You can patch CVE-2022-26440 by applying the patch with ID GN20220420037 provided by Mediatek.