CVE-2022-26473: Use After Free
Published Oct 7, 2022
·Updated
In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342197; Issue ID: ALPS07342197.
Affected Software
11 affected components
Google Android=12.0
MediaTek Mt6789
MediaTek Mt6855
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt8168
MediaTek Mt8365
MediaTek Mt8695
MediaTek Mt8696
MediaTek Mt8798
Event History
Oct 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-26473?
CVE-2022-26473 is a vulnerability in vdec fmt that could lead to local escalation of privilege with System execution privileges needed.
2
What is the severity of CVE-2022-26473?
The severity of CVE-2022-26473 is medium, with a severity value of 6.7.
3
Is user interaction needed for exploitation of CVE-2022-26473?
No, user interaction is not needed for exploitation of CVE-2022-26473.
4
How can I patch CVE-2022-26473?
To patch CVE-2022-26473, apply the patch with Patch ID ALPS07342197.
5
Where can I find more information about CVE-2022-26473?
More information about CVE-2022-26473 can be found at the following reference: [https://corp.mediatek.com/product-security-bulletin/October-2022]