CVE-2023-20842: Medium severity yocto project vulnerability
Published Sep 4, 2023
·Updated
In imgsyscmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue ID: ALPS07340477.
Affected Software
26 affected components
All of the following
Any of the following
linuxfoundation Yocto=4.0
MediaTek Iot Yocto=23.0
Google Android=11.0
Google Android=12.0
Linux Linux kernel=6.1
Any of the following
MediaTek Mt2713
MediaTek Mt6895
MediaTek Mt6897
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8781
linuxfoundation Yocto=4.0
MediaTek Iot Yocto=23.0
Google Android=11.0
Google Android=12.0
Linux Linux kernel=6.1
MediaTek Mt2713
MediaTek Mt6895
MediaTek Mt6897
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8781
Event History
Sep 4, 2023
CVE Published
via MITRE·02:27 AM
Data Sourced
via MITRE·02:27 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20842?
CVE-2023-20842 is a vulnerability in imgsys_cmdq that allows for a possible out of bounds write, leading to local escalation of privilege.
2
What software is affected by CVE-2023-20842?
Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0 and 12.0, and Linux Linux Kernel 6.1 are affected by CVE-2023-20842.
3
What is the severity of CVE-2023-20842?
The severity of CVE-2023-20842 is medium with a severity value of 6.5.
4
How can CVE-2023-20842 be exploited?
Exploiting CVE-2023-20842 requires user interaction.
5
How can I fix CVE-2023-20842?
Apply the patch with ID ALPS07354259 from the software vendor.