#VU80268 Out-of-bounds read in T610 and T618 - CVE-2022-47352


Vulnerability identifier: #VU80268

Vulnerability risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-47352

CWE-ID: CWE-125

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
T610
Mobile applications / Mobile firmware & hardware
T618
Mobile applications / Mobile firmware & hardware

Vendor: UNISOC

Description

The vulnerability allows a local application to manipulate or delete data.

The vulnerability exists due to a possible out of bounds read due to a missing bounds check within the Kernel. A local application can manipulate or delete data.

Mitigation
Install security update from vendor's website.

Vulnerable software versions

T610: All versions

T618: All versions


External links
https://www.unisoc.com/en_us/secy/announcementDetail/1698296481653522434


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability