CVE-2023-20850: Medium severity yocto project vulnerability
In imgsyscmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20850?
CVE-2023-20850 is a vulnerability in imgsys_cmdq that can lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation.
Which software versions are affected by CVE-2023-20850?
Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0 and 12.0, Linux Linux Kernel 6.1 are affected by CVE-2023-20850.
What is the severity of CVE-2023-20850?
CVE-2023-20850 has a severity level of 6.5 (medium).
How can CVE-2023-20850 be exploited?
CVE-2023-20850 requires user interaction to be exploited.
How can CVE-2023-20850 be fixed?
A patch with ID ALPS07340433 is available to fix CVE-2023-20850.