CVE-2024-20099: Medium severity yocto project vulnerability
Published Oct 7, 2024
·Updated
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.
Affected Software
9 affected components
All of the following
Any of the following
linuxfoundation Yocto=4.0
Google Android=12.0
Google Android=15.0
Any of the following
MediaTek Mt6768
MediaTek Mt6833
MediaTek Mt6853
MediaTek Mt6877
MediaTek Mt6893
MediaTek Mt8532
Event History
Oct 7, 2024
CVE Published
via MITRE·02:35 AM
Data Sourced
via MITRE·02:35 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-20099?
CVE-2024-20099 is considered a high-severity vulnerability due to its potential for local escalation of privilege.
2
How do I fix CVE-2024-20099?
To fix CVE-2024-20099, apply the patch identified by ALPS08997492.
3
What software versions are affected by CVE-2024-20099?
CVE-2024-20099 affects Yocto Project version 4.0 and Android versions 12.0 and 15.0.
4
Is user interaction required to exploit CVE-2024-20099?
No, user interaction is not needed for exploiting CVE-2024-20099.
5
What can happen if CVE-2024-20099 is exploited?
Exploitation of CVE-2024-20099 can lead to local escalation of privileges, allowing an attacker to execute actions with system-level permissions.