CVE-2023-20840: Medium severity yocto project vulnerability
In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID: ALPS07326430.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20840?
CVE-2023-20840 is a vulnerability in imgsys that allows for out of bounds read and write, potentially leading to local escalation of privilege with System execution privileges needed.
Which software is affected by CVE-2023-20840?
Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0, Google Android 12.0, and Linux Linux Kernel 6.1 are affected by CVE-2023-20840.
What is the severity of CVE-2023-20840?
CVE-2023-20840 has a severity rating of 6.5 (Medium).
How can the CVE-2023-20840 vulnerability be exploited?
Exploiting the CVE-2023-20840 vulnerability requires user interaction.
Is there a patch available for CVE-2023-20840?
Yes, a patch is available for CVE-2023-20840. Please refer to the Mediatek Product Security Bulletin for more information.