CVE-2023-20733: Use After Free
In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645149.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20733?
CVE-2023-20733 is a vulnerability in vcu that allows for a use after free due to improper locking, leading to potential escalation of privilege.
How severe is CVE-2023-20733?
CVE-2023-20733 has a severity value of 6.7, which is considered medium severity.
Which software is affected by CVE-2023-20733?
CVE-2023-20733 affects Linuxfoundation Iot-yocto 22.2, Linuxfoundation Yocto 4.0, Google Android 12.0, and Google Android 13.0.
Is user interaction needed to exploit CVE-2023-20733?
No, user interaction is not needed for exploitation of CVE-2023-20733.
How can I fix CVE-2023-20733?
To fix CVE-2023-20733, apply the patch ID ALPS07645149 or update the affected software with the provided fixes.