CVE-2024-20152: Medium severity yocto project vulnerability
In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20152?
The severity of CVE-2024-20152 is considered high due to its potential to cause local denial of service.
How do I fix CVE-2024-20152?
To fix CVE-2024-20152, apply the relevant patches identified by Patch IDs WCNCR00389047 or ALPS09136505.
What software is affected by CVE-2024-20152?
CVE-2024-20152 affects versions 3.3, 4.0, and 5.0 of Yocto Project, several Android versions including 13.0 to 15.0, and OpenWRT 23.05.
Is user interaction required to exploit CVE-2024-20152?
No, user interaction is not required to exploit CVE-2024-20152 once a malicious actor has obtained system privileges.
What type of vulnerability is CVE-2024-20152?
CVE-2024-20152 is a reachable assertion vulnerability due to improper exception handling in the wlan STA driver.