CVE-2025-20730: Medium severity linuxfoundation Yocto vulnerability
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS10068463
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20730?
CVE-2025-20730 has been classified as a high-severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2025-20730?
To fix CVE-2025-20730, apply the recommended patches as detailed in the security advisory associated with your affected software version.
Which software is affected by CVE-2025-20730?
CVE-2025-20730 affects several versions of Linux Foundation Yocto, RDK-B, and Google Android from versions 13.0 to 16.0.
Can CVE-2025-20730 be exploited remotely?
Exploitation of CVE-2025-20730 requires local access, as it is not remotely exploitable.
Is user interaction necessary for CVE-2025-20730 to be exploited?
No, user interaction is not needed for the exploitation of CVE-2025-20730.