CVE-2023-20638: Input Validation
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628537; Issue ID: ALPS07628537.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20638?
The severity of CVE-2023-20638 is medium with a CVSS score of 6.7.
How does CVE-2023-20638 impact Google Android versions 12.0 and 13.0?
CVE-2023-20638 impacts Google Android versions 12.0 and 13.0 by potentially allowing local escalation of privilege with system execution privileges.
Is Mediatek Mt6739 affected by CVE-2023-20638?
No, Mediatek Mt6739 is not affected by CVE-2023-20638.
How can I patch CVE-2023-20638?
To patch CVE-2023-20638, you can refer to the patch ID ALPS07628537 mentioned in the MediaTek product security bulletin.
Where can I find more information about CVE-2023-20638?
You can find more information about CVE-2023-20638 in the MediaTek product security bulletin of March 2023.