CVE-2023-20801

In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420968.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*

History

09 Aug 2023, 15:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4
First Time Mediatek mt8395
Linuxfoundation
Linuxfoundation yocto
Mediatek mt8781
Mediatek mt6895
Mediatek mt6879
Mediatek mt8188
Mediatek mt6983
Google android
Google
Mediatek
Mediatek mt8195
References (MISC) https://corp.mediatek.com/product-security-bulletin/August-2023 - (MISC) https://corp.mediatek.com/product-security-bulletin/August-2023 - Vendor Advisory
CPE cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
CWE CWE-362
CWE-416

07 Aug 2023, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-07 04:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-20801

Mitre link : CVE-2023-20801

CVE.ORG link : CVE-2023-20801


JSON object : View

Products Affected

linuxfoundation

  • yocto

mediatek

  • mt6879
  • mt8781
  • mt6983
  • mt8195
  • mt8395
  • mt6895
  • mt8188

google

  • android
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-416

Use After Free