Race Condition Vulnerability in aee Daemon by MediaTek
CVE-2025-20765

4.7MEDIUM

What is CVE-2025-20765?

A race condition has been identified in the aee daemon, leading to potential system crashes and localized denial of service. This vulnerability allows malicious actors with system privileges to exploit the flaw without requiring user interaction. To mitigate this risk, it is crucial for users to apply the latest patches provided by MediaTek.

Affected Version(s)

MT2718, MT2737, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6893, MT6895, MT6897, MT6899, MT6980D, MT6983, MT6985, MT6989, MT6990, MT6991, MT8113, MT8115, MT8139, MT8163, MT8168, MT8169, MT8183, MT8186, MT8188, MT8512, MT8516, MT8518, MT8519, MT8532, MT8676, MT8678, MT8695, MT8696, MT8698 Android 14.0, 15.0, 16.0 / openWRT 21.02, 23.05 / Yocto 4.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.