CVE-2025-20746: Medium severity linuxfoundation Yocto vulnerability
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20746?
CVE-2025-20746 is rated as a high severity vulnerability that can lead to local escalation of privilege.
How do I fix CVE-2025-20746?
To fix CVE-2025-20746, apply the patch identified as ALPS10010441.
Who is affected by CVE-2025-20746?
CVE-2025-20746 affects systems running Yocto version 4.0, RDK-B version 2024q1, Android versions 14.0 and 15.0, and OpenWrt versions 21.02.0 and 23.05.0.
Is user interaction required to exploit CVE-2025-20746?
No, user interaction is not needed for the exploitation of CVE-2025-20746.
What kind of vulnerability is CVE-2025-20746?
CVE-2025-20746 is an out of bounds write vulnerability due to an incorrect bounds check.