CVE-2025-20696: Medium severity linuxfoundation Yocto vulnerability
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09915215; Issue ID: MSV-3801.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS09915215
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20696?
CVE-2025-20696 has a moderate severity level as it can lead to local escalation of privilege with physical access.
How do I fix CVE-2025-20696?
To fix CVE-2025-20696, apply the available patch known as ALPS09915215 for the affected software versions.
What systems are affected by CVE-2025-20696?
CVE-2025-20696 affects specific versions of Yocto, RDK-B, and various Google Android and OpenWrt releases.
Is user interaction required to exploit CVE-2025-20696?
Yes, user interaction is required to exploit CVE-2025-20696.
Can CVE-2025-20696 lead to remote exploitation?
CVE-2025-20696 cannot lead to remote exploitation as it requires local physical access to the device.