VYPR
Unrated severityNVD Advisory· Published Mar 7, 2023· Updated Mar 6, 2025

CVE-2023-20640

CVE-2023-20640

Description

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629573; Issue ID: ALPS07629573.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds write in MediaTek ril component allows local escalation of privilege with System execution privileges; patch ID ALPS07629573.

Vulnerability

An out-of-bounds write vulnerability exists in the ril component of MediaTek chipsets due to a missing bounds check. This issue is present in software versions prior to the March 2023 security patch [1]. The vulnerability is identified by patch ID ALPS07629573 and is classified as Medium severity in the March 2023 MediaTek Product Security Bulletin [1].

Exploitation

An attacker with System execution privileges can trigger the vulnerability by sending crafted input to the ril component, bypassing bounds validation. No user interaction is needed for exploitation. The exact attack vector is not detailed in public references but requires local access and System-level permissions.

Impact

Successful exploitation allows the attacker to cause an out-of-bounds write, potentially corrupting memory. This can lead to local escalation of privilege, enabling the attacker to execute arbitrary code at a higher privilege level within the system.

Mitigation

The issue is fixed by patch ALPS07629573, which is included in the March 2023 MediaTek security bulletin [1]. Device OEMs were notified at least two months prior to publication. Users should apply the latest security updates from their device manufacturer. No workaround is available.

References
  1. March 2023

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • MediaTek, Inc./MT6879, MT6895, MT6983, MT8791, MT8791T, MT8797v5
    Range: Android 12.0, 13.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.