Security Bulletin

Summary
  • Security CVES
  • High CVE-2022-39131,CVE-2022-42771,CVE-2022-42770,CVE-2022-42775,CVE-2022-42756,CVE-2022-42754,CVE-2022-39134,CVE-2022-39106,CVE-2022-39132,CVE-2022-39130,CVE-2022-39129,CVE-2022-42755,CVE-2022-39133,CVE-2022-42772
  • Medium CVE-2022-42760,CVE-2022-42769,CVE-2022-42773,CVE-2022-42761,CVE-2022-42777,CVE-2022-39102,CVE-2022-39101,CVE-2022-39100,CVE-2022-39099,CVE-2022-39098,CVE-2022-39097,CVE-2022-39096,CVE-2022-39095,CVE-2022-39094,CVE-2022-39093,CVE-2022-39091,CVE-2022-39092,CVE-2022-39090,CVE-2022-42776,CVE-2022-42778,CVE-2022-42759,CVE-2022-42758,CVE-2022-42757,CVE-2022-42768,CVE-2022-42767,CVE-2022-42766,CVE-2022-42765,CVE-2022-42764,CVE-2022-42763,CVE-2022-42782,CVE-2022-42781,CVE-2022-42780,CVE-2022-42762,CVE-2022-42779,CVE-2022-42774
Minutia
  • CVE ID CVE-2022-39131
  • Title Improper input validation in camera driver
  • Description

    In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42771
  • Title Concurrent execution using shared resource with improper synchronization ('race condition') in wlan driver
  • Description

    In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8020

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42770
  • Title Concurrent execution using shared resource with improper synchronization ('race condition') in wlan driver
  • Description

    In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8019

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42775
  • Title Out-of-bounds read in camera driver
  • Description

    In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42756
  • Title Buffer overflow in sensor driver
  • Description

    In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-120 Classic Buffer Overflow
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42754
  • Title Memory use after free in npu driver
  • Description

    In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-416 Use After Free
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39134
  • Title Concurrent execution using shared resource with improper synchronization ('race condition') in audio driver
  • Description

    In audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39106
  • Title Stack Overflow in sensor driver
  • Description

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-121 Stack Overflow
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42760
  • Title Buffer overflow in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-120 Classic Buffer Overflow
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8018

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42769
  • Title Out-of-bounds read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-125 Out-of-bounds Read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8014

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42773
  • Title Out-of-bounds read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-125 Out-of-bounds Read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8001

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42761
  • Title Out-of-bounds read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-125 Out-of-bounds Read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42777
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.1
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39102
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39101
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39100
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39099
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39098
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39097
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39096
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39095
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39094
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39093
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39091
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39092
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39090
  • Title Elevation of privilege in power management service
  • Description

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 5.5
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42776
  • Title Elevation of privilege in UscAIEngine service
  • Description

    In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.4
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42778
  • Title Elevation of privilege windows manager service
  • Description

    In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android11

  • CVE ID CVE-2022-39132
  • Title Heap-based buffer overflow in camera driver
  • Description

    In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39130
  • Title Buffer over-read in face detect driver
  • Description

    In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39129
  • Title Stack-based buffer overflow in face detect driver
  • Description

    In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • Technology Area Kernel
  • Vulnerability Type CWE-121 Stack-based Buffer Overflow
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.7
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42755
  • Title Out-of-bounds write in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-787 Out-of-bounds Write
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8023

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-39133
  • Title Out-of-bounds write in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-787 Out-of-bounds Write
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8022

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42759
  • Title Buffer Over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8017

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42772
  • Title Out-of-bounds write in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-787 Out-of-bounds Write
  • Access Vector Local
  • CVSS Rating High
  • CVSS Score 7.3
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8021

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42758
  • Title Buffer Over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8016

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42757
  • Title Buffer Over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8015

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42768
  • Title Buffer over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8013

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42767
  • Title Integer overflow in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-190 Integer Overflow
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8012

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42766
  • Title Information disclosure in wlan driver
  • Description

    In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-200 Information Disclosure
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8011

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42765
  • Title Integer overflow in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-190 Integer Overflow
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8010

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42764
  • Title Integer overflow in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-190 Integer Overflow
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8009

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42763
  • Title Integer overflow in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-190 Integer Overflow
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8008

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42782
  • Title Information Disclosure in wlan driver
  • Description

    In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-200 Information Disclosure
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8007

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42781
  • Title Buffer over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8006

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42780
  • Title Buffer over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8005

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42762
  • Title Buffer over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8004

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42779
  • Title Buffer over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8003

  • Affected Software Versions

    Android10/Android11/Android12

  • CVE ID CVE-2022-42774
  • Title Buffer over-read in wlan driver
  • Description

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • Technology Area WLAN Firmware
  • Vulnerability Type CWE-126 Buffer Over-read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 6.6
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
  • Affected Chipsets*

    SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8002

  • Affected Software Versions

    Android10/Android11/Android12

*The list of affected chipsets may not be complete. For latest information, device OEMs can contact directly at https://unisupport.unisoc.com

Vulnerability type definition
  • Abbreviation Interpretation
  • RCE Remote Code Execution
  • EoP Elevation of Privilege
  • ID Information Disclosure
  • DoS Denial of Service
  • N/A Classification not available
Version
  • Version Date Description
  • 1.0 2022-12-05