CVE-2025-20651: Medium severity yocto project vulnerability
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2062.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20651?
The severity of CVE-2025-20651 is rated as medium due to the potential for local information disclosure.
How do I fix CVE-2025-20651?
To fix CVE-2025-20651, you should apply the patch identified as ALPS09291294 as soon as possible.
What software versions are affected by CVE-2025-20651?
CVE-2025-20651 affects Yocto Project version 4.0, Android versions 13.0, 14.0, and 15.0, as well as specific versions of RDK Central RDKB.
Can CVE-2025-20651 be exploited remotely?
No, CVE-2025-20651 requires local physical access to the device for exploitation.
What type of vulnerability is CVE-2025-20651?
CVE-2025-20651 is classified as an out of bounds read vulnerability.