CVE-2024-20054: Medium severity yocto project vulnerability
In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20054?
CVE-2024-20054 is considered a high severity vulnerability due to the potential for local escalation of privilege.
How do I fix CVE-2024-20054?
To fix CVE-2024-20054, it is recommended to apply the patch provided in Patch ID: ALPS08580200.
What type of vulnerability is CVE-2024-20054?
CVE-2024-20054 is a privilege escalation vulnerability caused by a missing bounds check.
Is user interaction required to exploit CVE-2024-20054?
No, user interaction is not needed for the exploitation of CVE-2024-20054.
Which software versions are affected by CVE-2024-20054?
CVE-2024-20054 affects specific versions of Yocto Project, Android, and OpenWrt including Yocto 2.6, Yocto 3.3, Android 13.0, and Android 14.0.