Description
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- MediaTek, Inc. / MT2713, MT6895, MT6897, MT6983, MT8188, MT8195, MT8395, MT8781Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0 – Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0