CVE-2020-0256: High severity Google Android vulnerability
In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-152874864
Other sources
The potential out of bounds write in LoadPartitionTable of gpt.cc due to missing bounds check in gdisk utility. Exploitation requires the use of a malicious storage (such as: USB) device that could cause a crash and possibly allows local privilege escalation.
References: https://packetstormsecurity.com/files/165869/USN-5262-1 https://sourceforge.net/p/gptfdisk/code/ci/81c8bbee46ad6ebacf72eae70ba5147f376205a4/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0256?
CVE-2020-0256 has a high severity rating due to its potential for local escalation of privilege through an out-of-bounds write.
How do I fix CVE-2020-0256?
To mitigate CVE-2020-0256, ensure that your device is updated to the latest security patch provided by the vendor.
Which software versions are affected by CVE-2020-0256?
CVE-2020-0256 affects Google Android versions 8.0, 8.1, 9.0, and 10.0, along with Debian GNU/Linux version 9.0.
Is user interaction required to exploit CVE-2020-0256?
No, user interaction is not needed for the exploitation of CVE-2020-0256.
What type of attack does CVE-2020-0256 expose systems to?
CVE-2020-0256 exposes systems to possible local escalation of privilege when a malicious USB device is inserted.