First published: Tue Jan 03 2023(Updated: )
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705066; Issue ID: GN20220705066.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
MediaTek MT7603 Firmware | =7.6.6.0 | |
Yocto Project | =3.1 | |
Yocto Project | =3.3 | |
MediaTek MT7603 Firmware | ||
MediaTek MT7613 Firmware | =7.6.6.0 | |
MediaTek MT7613 | ||
MediaTek MT7615 Firmware | =7.6.6.0 | |
MediaTek MT7615 Firmware | ||
MediaTek MT7622 | =7.6.6.0 | |
MediaTek MT7622 Firmware | ||
mediatek mt7628 firmware | =7.6.6.0 | |
MediaTek MT7628 | ||
MediaTek MT7629 | =7.6.6.0 | |
MediaTek MT7629 Firmware | ||
mediatek mt7915 firmware | =7.6.6.0 | |
Mediatek MT7915 | ||
MediaTek MT7916 | =7.6.6.0 | |
MediaTek MT7916 Firmware | ||
MediaTek MT7981 Firmware | =7.6.6.0 | |
MediaTek MT7981 Firmware | ||
MediaTek MT7986 Firmware | =7.6.6.0 | |
MediaTek MT7986 | ||
MediaTek MT8518S Firmware | =7.6.6.0 | |
MediaTek MT8518S Firmware | ||
Mediatek MT8532 Firmware | =7.6.6.0 | |
MediaTek MT8532 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-32659 is medium.
No, user interaction is not needed for exploitation of CVE-2022-32659.
The patch ID for CVE-2022-32659 is GN20220705066.
The affected software versions are: mt7603_firmware 7.6.6.0, yocto 3.1, yocto 3.3, mt7613_firmware 7.6.6.0, mt7615_firmware 7.6.6.0, mt7622_firmware 7.6.6.0, mt7628_firmware 7.6.6.0, mt7629_firmware 7.6.6.0, mt7915_firmware 7.6.6.0, mt7916_firmware 7.6.6.0, mt7981_firmware 7.6.6.0, mt7986_firmware 7.6.6.0, mt8518s_firmware 7.6.6.0, mt8532_firmware 7.6.6.0.
The Common Weakness Enumeration (CWE) ID for CVE-2022-32659 is 755.