CVE-2024-20138: Input Validation
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20138?
CVE-2024-20138 has a severity level indicating a potential out of bound read that could lead to remote information disclosure.
How do I fix CVE-2024-20138?
To fix CVE-2024-20138, apply the provided patch ID ALPS08998291 immediately.
Which devices are affected by CVE-2024-20138?
CVE-2024-20138 affects devices using certain versions of the Mediatek software development kit and specific versions of Android.
Is user interaction required to exploit CVE-2024-20138?
No, user interaction is not needed to exploit CVE-2024-20138.
What type of vulnerability is CVE-2024-20138?
CVE-2024-20138 is classified as an out of bound read vulnerability due to improper input validation.