CVE-2025-20671: Race Condition
Published May 5, 2025
·Updated
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09698599; Issue ID: MSV-3228.
Affected Software
12 affected components
All of the following
Any of the following
Google Android=14.0
Google Android=15.0
Any of the following
MediaTek Mt2718
MediaTek Mt6878
MediaTek Mt6897
MediaTek Mt6899
MediaTek Mt6989
MediaTek Mt6991
MediaTek Mt8196
MediaTek Mt8391
MediaTek Mt8676
MediaTek Mt8678
Event History
May 5, 2025
CVE Published
via MITRE·02:49 AM
Data Sourced
via MITRE·02:49 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-20671?
CVE-2025-20671 has a high severity as it can lead to local escalation of privilege due to an out of bounds write.
2
How do I fix CVE-2025-20671?
To fix CVE-2025-20671, apply the patch identified by Patch ID: ALPS09698599.
3
Who is affected by CVE-2025-20671?
CVE-2025-20671 affects devices running Android versions 14.0 and 15.0.
4
Can CVE-2025-20671 be exploited without user interaction?
Yes, exploitation of CVE-2025-20671 does not require user interaction.
5
What can result from the exploitation of CVE-2025-20671?
Exploitation of CVE-2025-20671 may lead to local escalation of privilege for a malicious actor.