The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
The product reads data past the end, or before the beginning, of the intended buffer.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://consumer.huawei.com/en/support/bulletin/2022/10/ | vendor advisory |
https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202210-0000001416095697 | vendor advisory |