Memory corruption in MediaTek products - CVE-2024-20076

 

Memory corruption in MediaTek products - CVE-2024-20076

Published: July 1, 2024


Vulnerability identifier: #VU93556
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20076
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to perform service disruption.

The vulnerability exists due to incorrect error handling within Modem. A local application can perform service disruption.


Affected software

MT6771
MT8788
MT8786
MT8781
MT8768
MT8766
MT8765
MT8667
MT8666
MT2731
MT6769
MT6768
MT6767
MT6765
MT6763
MT6762
MT6761
MT6739
Google Android

How to mitigate CVE-2024-20076

Install security update from vendor's website.

Google Android - addressed in versions 12L 2024-07-05, 12 2024-07-05, 13 2024-07-05, 14 2024-07-05

External References

Related Security Bulletins