CVE-2022-40761: High severity samsung mTower vulnerability
Published Sep 16, 2022
·Updated
The function teeobjfree in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEEAllocateOperation with a disturbed heap layout, related to uteecrypobjalloc.
Affected Software
1 affected component
samsung mTower<=0.3.0
Remediation
Event History
Sep 16, 2022
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40761?
CVE-2022-40761 has been assessed as a Denial of Service vulnerability.
2
How do I fix CVE-2022-40761?
To mitigate CVE-2022-40761, upgrade to a version of Samsung mTower greater than 0.3.0.
3
What is the impact of CVE-2022-40761?
CVE-2022-40761 allows a trusted application to cause a Denial of Service by disrupting heap layout.
4
Which software is affected by CVE-2022-40761?
Samsung mTower versions up to and including 0.3.0 are affected by CVE-2022-40761.
5
Who can exploit CVE-2022-40761?
CVE-2022-40761 can be exploited by a trusted application running within the Samsung mTower environment.