CVE-2024-20081: Input Validation
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20081?
CVE-2024-20081 has a severity rating of high due to the potential for local escalation of privilege.
How do I fix CVE-2024-20081?
To fix CVE-2024-20081, apply the patch ID ALPS08719602 provided by the vendor.
Who is affected by CVE-2024-20081?
CVE-2024-20081 affects Yocto Project versions 2.6, 3.3, and 4.0, Google Android versions 13.0 and 14.0, as well as specific versions of OpenWrt.
Is user interaction required to exploit CVE-2024-20081?
No, user interaction is not needed for exploitation of CVE-2024-20081.
What kind of vulnerability is CVE-2024-20081?
CVE-2024-20081 is an out of bounds write vulnerability caused by improper input validation in the GNSS service.