First published: Mon Sep 04 2023(Updated: )
In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID: ALPS07326430.
Credit: security@mediatek.com security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Yocto | =4.0 | |
Mediatek Iot Yocto | =23.0 | |
Google Android | =11.0 | |
Google Android | =12.0 | |
Linux Linux kernel | =6.1 | |
Mediatek Mt6895 | ||
Mediatek Mt6897 | ||
Mediatek Mt6983 | ||
Mediatek Mt8188 | ||
Mediatek Mt8195 | ||
Mediatek Mt8395 | ||
All of | ||
Any of | ||
Linuxfoundation Yocto | =4.0 | |
Mediatek Iot Yocto | =23.0 | |
Google Android | =11.0 | |
Google Android | =12.0 | |
Linux Linux kernel | =6.1 | |
Any of | ||
Mediatek Mt6895 | ||
Mediatek Mt6897 | ||
Mediatek Mt6983 | ||
Mediatek Mt8188 | ||
Mediatek Mt8195 | ||
Mediatek Mt8395 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20840 is a vulnerability in imgsys that allows for out of bounds read and write, potentially leading to local escalation of privilege with System execution privileges needed.
Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0, Google Android 12.0, and Linux Linux Kernel 6.1 are affected by CVE-2023-20840.
CVE-2023-20840 has a severity rating of 6.5 (Medium).
Exploiting the CVE-2023-20840 vulnerability requires user interaction.
Yes, a patch is available for CVE-2023-20840. Please refer to the Mediatek Product Security Bulletin for more information.