CVE-2024-20085: Medium severity yocto project vulnerability
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20085?
CVE-2024-20085 has a medium severity rating due to the potential for local information disclosure without user interaction.
How do I fix CVE-2024-20085?
To fix CVE-2024-20085, apply the provided patches from the vendor as soon as they become available.
What software is affected by CVE-2024-20085?
CVE-2024-20085 affects multiple versions of Yocto Project, RDK Central RDKB, and Android versions 13.0 and 14.0.
Is user interaction required to exploit CVE-2024-20085?
No, user interaction is not needed for the exploitation of CVE-2024-20085.
What kind of impact does CVE-2024-20085 have?
CVE-2024-20085 can lead to a possible out of bounds read, resulting in local information disclosure.