Use-after-free in MediaTek products - CVE-2022-26451

 

Use-after-free in MediaTek products - CVE-2022-26451

Published: September 5, 2022


Vulnerability identifier: #VU66961
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26451
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to improper synchronization in ged. A local user can gain elevated privileges on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

MT6789
MT6855
MT6879
MT6895
MT6983
MT8168
MT8365

How to mitigate CVE-2022-26451

Install updates from vendor's website.


External References

Related Security Bulletins