CVE-2023-20954: Critical severity android vulnerability
In SDPAddAttribute of sdpdb.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261867748
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20954?
CVE-2023-20954 is considered a high-severity vulnerability that could lead to remote code execution.
How do I fix CVE-2023-20954?
To fix CVE-2023-20954, users should update their Android devices to the latest security version released by Google.
What products are affected by CVE-2023-20954?
CVE-2023-20954 affects Android versions 11.0, 12.0, 12.1, and 13.0.
Is user interaction required to exploit CVE-2023-20954?
No, exploitation of CVE-2023-20954 does not require user interaction.
What type of vulnerability is CVE-2023-20954?
CVE-2023-20954 is classified as a possible out of bounds write vulnerability.