CVE-2023-20796: Medium severity yocto project vulnerability
In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929790; Issue ID: ALPS07929790.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20796?
The severity of CVE-2023-20796 is medium (4.4).
How can CVE-2023-20796 be exploited?
CVE-2023-20796 can be exploited without user interaction.
What software is affected by CVE-2023-20796?
The affected software includes Linuxfoundation Yocto version 2.6 and 3.3, Rdkcentral Rdk-b version 2022q3, Google Android version 12.0 and 13.0, Openwrt Openwrt version 19.07.0 and 21.02.0.
How can I fix CVE-2023-20796?
To fix CVE-2023-20796, apply the patch ID: ALPS07929790.
Where can I find more information about CVE-2023-20796?
More information about CVE-2023-20796 can be found at the following link: [https://corp.mediatek.com/product-security-bulletin/August-2023](https://corp.mediatek.com/product-security-bulletin/August-2023).