CVE-2024-20146: Input Validation
In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20146?
CVE-2024-20146 has a high severity rating due to the risk of remote code execution without additional privileges.
How do I fix CVE-2024-20146?
To fix CVE-2024-20146, apply the security patches identified as WCNCR00389496 or ALPS09137491.
Which software versions are affected by CVE-2024-20146?
CVE-2024-20146 affects specific versions of the Google Android operating system.
Does CVE-2024-20146 require user interaction for exploitation?
No, CVE-2024-20146 does not require any user interaction for exploitation.
What type of vulnerability is CVE-2024-20146?
CVE-2024-20146 is an out of bounds write vulnerability due to improper input validation in the wlan STA driver.