CVE-2025-20656: Medium severity linuxfoundation Yocto vulnerability
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09625423; Issue ID: MSV-3033.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20656?
CVE-2025-20656 is classified as a high severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2025-20656?
To fix CVE-2025-20656, apply the patch identified as ALPS09625423 as soon as possible.
Who is affected by CVE-2025-20656?
CVE-2025-20656 affects devices running specified versions of Yocto, Android, OpenWRT, and certain MediaTek chipsets.
What type of vulnerability is CVE-2025-20656?
CVE-2025-20656 is an out-of-bounds write vulnerability due to a missing bounds check.
Is user interaction required to exploit CVE-2025-20656?
No, user interaction is not needed to exploit CVE-2025-20656, making it particularly dangerous.