CVE-2026-20435: Medium severity linuxfoundation Yocto vulnerability
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20435?
CVE-2026-20435 has a moderate severity rating due to potential local information disclosure.
How do I fix CVE-2026-20435?
To fix CVE-2026-20435, apply the official patches provided by the affected software vendors.
What are the affected systems for CVE-2026-20435?
CVE-2026-20435 affects multiple systems including specific versions of Yocto, RDK-B, Android, and OpenWrt.
Can CVE-2026-20435 be exploited remotely?
No, CVE-2026-20435 requires physical access to the device for exploitation.
Is user interaction required to exploit CVE-2026-20435?
No, user interaction is not required for exploiting CVE-2026-20435.