
CVE-2022-20046
https://notcve.org/view.php?id=CVE-2022-20046
09 Feb 2022 — In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS06142410. En Bluetooth, se presenta una posible corrupción de memoria debido a un error lógico. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-401: Missing Release of Memory after Effective Lifetime •

CVE-2022-20045
https://notcve.org/view.php?id=CVE-2022-20045
09 Feb 2022 — In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID: ALPS06126820. En Bluetooth, se presenta un posible bloqueo del servicio debido a un uso de memoria previamente liberada. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-416: Use After Free •

CVE-2022-20044
https://notcve.org/view.php?id=CVE-2022-20044
09 Feb 2022 — In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID: ALPS06126814. En Bluetooth, se presenta un posible bloqueo del servicio debido a un uso de memoria previamente liberada. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-416: Use After Free •

CVE-2022-20043
https://notcve.org/view.php?id=CVE-2022-20043
09 Feb 2022 — In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06148177; Issue ID: ALPS06148177. En Bluetooth, se presenta una posible escalada de privilegios debido a una falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-862: Missing Authorization •

CVE-2022-20041
https://notcve.org/view.php?id=CVE-2022-20041
09 Feb 2022 — In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108596; Issue ID: ALPS06108596. En Bluetooth, se presenta una posible escalada de privilegios debido a una falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-862: Missing Authorization •

CVE-2022-20042
https://notcve.org/view.php?id=CVE-2022-20042
09 Feb 2022 — In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108487; Issue ID: ALPS06108487. En Bluetooth, se presenta una posible divulgación de información debido a un manejo incorrecto de errores. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-755: Improper Handling of Exceptional Conditions •

CVE-2022-20040
https://notcve.org/view.php?id=CVE-2022-20040
09 Feb 2022 — In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219150; Issue ID: ALPS06219150. En power_hal_manager_service, se presenta una posible omisión de permisos debido a un desbordamiento del búfer en la región stack de la memoria. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-787: Out-of-bounds Write •

CVE-2022-20039
https://notcve.org/view.php?id=CVE-2022-20039
09 Feb 2022 — In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183345; Issue ID: ALPS06183345. En ccu driver, se presenta una posible corrupción de memoria debido a un desbordamiento de enteros. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-190: Integer Overflow or Wraparound •

CVE-2022-20038
https://notcve.org/view.php?id=CVE-2022-20038
09 Feb 2022 — In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Issue ID: ALPS06183335. En ccu driver, se presenta una posible corrupción de memoria debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-787: Out-of-bounds Write •

CVE-2022-20037
https://notcve.org/view.php?id=CVE-2022-20037
09 Feb 2022 — In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID: ALPS06171705. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •