First published: Mon Aug 01 2022(Updated: )
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420088; Issue ID: GN20220420088.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mediatek Mt7603 Firmware | =7.6.2.3 | |
Mediatek Mt7603 | ||
Mediatek Mt7610 Firmware | =7.6.2.3 | |
Mediatek Mt7610 | ||
Mediatek Mt7612 Firmware | =7.6.2.3 | |
Mediatek Mt7612 | ||
Mediatek Mt7613 Firmware | =7.6.2.3 | |
Mediatek Mt7613 | ||
Mediatek Mt7615 Firmware | =7.6.2.3 | |
Mediatek Mt7615 | ||
Mediatek Mt7620 Firmware | =7.6.2.3 | |
Mediatek Mt7620 | ||
Mediatek Mt7622 Firmware | =7.6.2.3 | |
Mediatek Mt7622 | ||
Mediatek Mt7628 Firmware | =7.6.2.3 | |
Mediatek Mt7628 | ||
Mediatek Mt7629 Firmware | =7.6.2.3 | |
Mediatek Mt7629 | ||
Mediatek Mt7915 Firmware | =7.6.2.3 | |
Mediatek Mt7915 | ||
Mediatek Mt7916 Firmware | =7.6.2.3 | |
Mediatek Mt7916 | ||
Mediatek Mt7986 Firmware | =7.6.2.3 | |
Mediatek Mt7986 | ||
Mediatek Mt8981 Firmware | =7.6.2.3 | |
Mediatek Mt8981 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26445 is a vulnerability in the wifi driver that allows for a possible out of bounds write due to a missing bounds check.
The severity of CVE-2022-26445 is medium with a CVSS score of 6.7.
CVE-2022-26445 can be exploited locally without the need for user interaction.
The affected software versions are Mediatek Mt7603 Firmware 7.6.2.3 and Mediatek Mt7610 Firmware 7.6.2.3.
No, Mediatek Mt7610 is not vulnerable to CVE-2022-26445.