CVE-2023-20681

In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07696134; Issue ID: ALPS07696134.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781wifi:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791wifi:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8795t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797wifi:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*

History

12 Apr 2023, 19:42

Type Values Removed Values Added
CPE cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791wifi:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8795t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797wifi:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781wifi:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
References (MISC) https://corp.mediatek.com/product-security-bulletin/April-2023 - (MISC) https://corp.mediatek.com/product-security-bulletin/April-2023 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7
First Time Mediatek mt8795t
Google
Mediatek mt8791
Mediatek mt8798
Mediatek mt8791wifi
Mediatek
Mediatek mt8781wifi
Mediatek mt6985
Mediatek mt6886
Mediatek mt8771
Mediatek mt8365
Mediatek mt6983
Mediatek mt6895
Mediatek mt8791t
Google android
Mediatek mt8797
Mediatek mt8797wifi
Mediatek mt8781
CWE CWE-787

06 Apr 2023, 19:50

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-06 18:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-20681

Mitre link : CVE-2023-20681

CVE.ORG link : CVE-2023-20681


JSON object : View

Products Affected

mediatek

  • mt8795t
  • mt6895
  • mt8771
  • mt8791
  • mt8791t
  • mt6886
  • mt8791wifi
  • mt8798
  • mt8365
  • mt8781wifi
  • mt8781
  • mt8797
  • mt6985
  • mt8797wifi
  • mt6983

google

  • android
CWE
CWE-787

Out-of-bounds Write