Heap-based buffer overflow in MediaTek products - CVE-2022-21768

 

Heap-based buffer overflow in MediaTek products - CVE-2022-21768

Published: July 8, 2022


Vulnerability identifier: #VU65032
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21768
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within Bluetooth implementation. A remote attacker with physical proximity to device can trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

MT8167S
MT8175
MT8183
MT8362A
MT8365
MT8385
Google Android

How to mitigate CVE-2022-21768

Install updates from vendor's website.

Google Android - addressed in versions 10 2022-07-05, 11 2022-07-05, 12L 2022-07-05, 12 2022-07-05

External References

Related Security Bulletins