In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
History

Fri, 07 Feb 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2021-11-03'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2025-02-07T13:03:36.836Z

Reserved: 2019-10-17T00:00:00.000Z

Link: CVE-2020-0069

cve-icon Vulnrichment

Updated: 2024-08-04T05:47:40.759Z

cve-icon NVD

Status : Modified

Published: 2020-03-10T20:15:21.947

Modified: 2025-02-07T13:15:28.787

Link: CVE-2020-0069

cve-icon Redhat

No data.