CVE-2023-20844: Medium severity yocto project vulnerability
Published Sep 4, 2023
·Updated
In imgsyscmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Issue ID: ALPS07340121.
Affected Software
12 affected components
linuxfoundation Yocto=4.0
MediaTek Iot Yocto=23.0
Google Android=11.0
Google Android=12.0
Linux Linux kernel=6.1
MediaTek Mt6895
MediaTek Mt6897
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8781
Event History
Sep 4, 2023
CVE Published
via MITRE·02:27 AM
Data Sourced
via MITRE·02:27 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20844?
CVE-2023-20844 is a vulnerability in imgsys_cmdq that allows for a possible out-of-bounds read, leading to local information disclosure.
2
What is the severity of CVE-2023-20844?
The severity of CVE-2023-20844 is medium, with a CVSS score of 4.2.
3
Which software versions are affected by CVE-2023-20844?
Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0 and 12.0, and Linux Linux Kernel 6.1 are affected by CVE-2023-20844.
4
What is the patch ID for CVE-2023-20844?
The patch ID for CVE-2023-20844 is ALPS07354058.
5
Is user interaction needed to exploit CVE-2023-20844?
Yes, user interaction is needed to exploit CVE-2023-20844.