CVE-2023-32836: Integer Overflow
Published Nov 6, 2023
·Updated
In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08126725; Issue ID: ALPS08126725.
Affected Software
10 affected components
Google Android
All of the following
Any of the following
Google Android=11.0
Google Android=12.0
Google Android=13.0
Any of the following
MediaTek Mt6893
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt6985
MediaTek Mt8797
MediaTek Mt8798
Event History
Nov 6, 2023
CVE Published
via Android·12:00 AM
CVE Published
via MITRE·03:50 AM
Data Sourced
via MITRE·03:50 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32836?
The severity of CVE-2023-32836 is medium.
2
What software versions are affected by CVE-2023-32836?
CVE-2023-32836 affects Google Android versions 11.0, 12.0, and 13.0.
3
Is Mediatek Mt6893 vulnerable to CVE-2023-32836?
No, Mediatek Mt6893 is not vulnerable to CVE-2023-32836.
4
How can I mitigate the risk of CVE-2023-32836?
Apply the provided patch with ID: ALPS08126725 to fix CVE-2023-32836.
5
Where can I find more information about CVE-2023-32836?
You can find more information about CVE-2023-32836 at the following link: https://corp.mediatek.com/product-security-bulletin/November-2023