CVE-2024-20134: Medium severity android vulnerability
Published Dec 2, 2024
·Updated
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09154589; Issue ID: MSV-1866.
Affected Software
16 affected components
All of the following
Any of the following
Google Android=13.0
Google Android=14.0
Google Android=15.0
Any of the following
MediaTek Mt6835
MediaTek Mt6878
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6896
MediaTek Mt6897
MediaTek Mt6983
MediaTek Mt6985
MediaTek Mt6989
MediaTek Mt8755
MediaTek Mt8775
MediaTek Mt8796
MediaTek Mt8798
Event History
Dec 2, 2024
CVE Published
via MITRE·03:07 AM
Data Sourced
via MITRE·03:07 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-20134?
The severity of CVE-2024-20134 is high as it allows for local escalation of privileges.
2
How do I fix CVE-2024-20134?
To fix CVE-2024-20134, apply the patch indicated by Patch ID ALPS09154589.
3
Does CVE-2024-20134 require user interaction for exploitation?
No, CVE-2024-20134 does not require user interaction for exploitation.
4
Which versions of Android are affected by CVE-2024-20134?
CVE-2024-20134 affects Android versions 13.0, 14.0, and 15.0.
5
What could be the potential impact of CVE-2024-20134?
The potential impact of CVE-2024-20134 includes local escalation of privilege, allowing unauthorized access to system features.