Use-after-free in MediaTek products - CVE-2022-26451
Published: September 5, 2022
Vulnerability identifier: #VU66961
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26451
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to improper synchronization in ged. A local user can gain elevated privileges on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
MT6789
MT6855
MT6879
MT6895
MT6983
MT8168
MT8365
MT6855
MT6879
MT6895
MT6983
MT8168
MT8365
How to mitigate CVE-2022-26451
Install updates from vendor's website.