CVE-2024-20089: High severity yocto project vulnerability
Published Sep 2, 2024
·Updated
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
Affected Software
18 affected components
All of the following
Any of the following
linuxfoundation Yocto=2.6
linuxfoundation Yocto=3.3
linuxfoundation Yocto=4.0
Rdkcentral Rdk-b=2022q3
Google Android=13.0
Google Android=14.0
Any of the following
MediaTek Mt6835
MediaTek Mt6878
MediaTek Mt6886
MediaTek Mt6897
MediaTek Mt6980
MediaTek Mt6985
MediaTek Mt6989
MediaTek Mt6990
MediaTek Mt8678
MediaTek Mt8775
MediaTek Mt8792
MediaTek Mt8796
Event History
Sep 2, 2024
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-20089?
CVE-2024-20089 has a moderate severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2024-20089?
To fix CVE-2024-20089, apply the patch identified as ALPS08861558 provided by the affected software vendor.
3
What systems are affected by CVE-2024-20089?
CVE-2024-20089 affects specific versions of Yocto, RDK Central RDKB, and Google Android.
4
Is user interaction required to exploit CVE-2024-20089?
No, user interaction is not needed for the exploitation of CVE-2024-20089.
5
Can CVE-2024-20089 be exploited remotely?
Yes, CVE-2024-20089 can be exploited remotely, leading to a denial of service.