Out of Bounds Read Vulnerability in MediaTek Products
CVE-2023-20847
4.2MEDIUM
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 4 September 2023
What is CVE-2023-20847?
A vulnerability in imgsys_cmdq has been identified which allows for a potential out of bounds read. This flaw arises from the absence of proper range checking, potentially leading to a local denial of service scenario. Successful exploitation of this vulnerability necessitates user interaction and requires system execution privileges. MediaTek has issued a patch identified as ALPS07354025 to mitigate this issue.
Affected Version(s)
MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781 Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0