CVE-2022-40760: Buffer Overflow
A Buffer Access with Incorrect Length Value vulnerablity in the TEEMACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEEMACUpdate with an excessive size value of chunkSize.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40760?
CVE-2022-40760 has been classified as a high severity vulnerability due to its potential to cause Denial of Service.
How does CVE-2022-40760 exploit the TEE_MACUpdate function?
CVE-2022-40760 allows a trusted application to trigger a Denial of Service by invoking TEE_MACUpdate with an excessively large chunkSize.
Is there a patch available for CVE-2022-40760?
Yes, a patch is available that addresses CVE-2022-40760 by validating the length value before processing the chunk.
Which versions of Samsung mTower are affected by CVE-2022-40760?
CVE-2022-40760 affects Samsung mTower versions up to and including 0.3.0.
What mitigation strategies can be employed for CVE-2022-40760?
Mitigation strategies for CVE-2022-40760 include updating to the latest version of Samsung mTower and ensuring proper input validation in applications.