CVE-2022-21789
https://notcve.org/view.php?id=CVE-2022-21789
In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: ALPS06478101. En audio ipi, se presenta una posible corrupción de memoria debido a una condición de carrera. • https://github.com/docfate111/CVE-2022-21789 https://corp.mediatek.com/product-security-bulletin/August-2022 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2022-21787
https://notcve.org/view.php?id=CVE-2022-21787
In audio DSP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558844; Issue ID: ALPS06558844. En audio DSP, se presenta una posible escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/July-2022 • CWE-787: Out-of-bounds Write •
CVE-2022-21786
https://notcve.org/view.php?id=CVE-2022-21786
In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558822; Issue ID: ALPS06558822. En audio DSP, Se presenta una posible corrupción de memoria debido a una fundición inapropiada. • https://corp.mediatek.com/product-security-bulletin/July-2022 • CWE-704: Incorrect Type Conversion or Cast •
CVE-2022-21776
https://notcve.org/view.php?id=CVE-2022-21776
In MDP, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545450; Issue ID: ALPS06545450. En MDP, Se presenta un posible uso de memoria previamente liberada debido a una condición de carrera. • https://corp.mediatek.com/product-security-bulletin/July-2022 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2022-21770
https://notcve.org/view.php?id=CVE-2022-21770
In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558663; Issue ID: ALPS06558663. En sound driver, Se presenta una posible divulgación de información debido al seguimiento de enlaces simbólicos. • https://corp.mediatek.com/product-security-bulletin/July-2022 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •