CVE-2022-26466: Integer Overflow
In audio ipi, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558777; Issue ID: ALPS06558777.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26466?
CVE-2022-26466 is a vulnerability in audio ipi that allows for a possible out of bounds write due to an integer overflow.
What is the severity of CVE-2022-26466?
The severity of CVE-2022-26466 is medium with a CVSS score of 6.7.
How can CVE-2022-26466 be exploited?
CVE-2022-26466 can be exploited locally without user interaction, leading to local escalation of privilege with System execution privileges needed.
Which software and versions are affected by CVE-2022-26466?
Google Android versions 11.0 and 12.0, and Yoctoproject Yocto version 3.1 are affected by CVE-2022-26466.
Is Mediatek Mt6779 vulnerable to CVE-2022-26466?
No, Mediatek Mt6779 is not vulnerable to CVE-2022-26466.