CVE-2023-20849: Use After Free
In imgsyscmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20849?
CVE-2023-20849 is a vulnerability in imgsys_cmdq that allows for a use after free, potentially leading to local escalation of privilege.
What software versions are affected by CVE-2023-20849?
Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0 and 12.0, and Linux Linux Kernel 6.1 are affected by CVE-2023-20849.
How severe is CVE-2023-20849?
CVE-2023-20849 has a severity rating of 6.5 out of 10, making it a medium-severity vulnerability.
What is the patch ID for CVE-2023-20849?
The patch ID for CVE-2023-20849 is ALPS07340433.
Is user interaction required for exploitation of CVE-2023-20849?
Yes, user interaction is needed for the exploitation of CVE-2023-20849.