First published: Mon Nov 04 2024(Updated: )
In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Android | =13.0 | |
Android | =14.0 | |
Any of | ||
MediaTek MT6878 | ||
MediaTek MT6886 | ||
MediaTek MT6897 | ||
MediaTek MT6985T | ||
MediaTek MT8676 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20112 is classified as a local denial of service vulnerability requiring system execution privileges and user interaction.
To mitigate CVE-2024-20112, apply the patch identified as ALPS09071481 to affected systems.
CVE-2024-20112 affects Android versions 13.0 and 14.0.
Exploitation of CVE-2024-20112 can result in a local denial of service.
Yes, user interaction is necessary for exploiting CVE-2024-20112.