VYPR
Medium severity6.6NVD Advisory· Published Apr 1, 2024· Updated Jun 17, 2026

CVE-2024-20054

CVE-2024-20054

Description

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • MediaTek, Inc./MT2735, MT2737, MT6762, MT6765, MT6769, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT6895, MT6983, MT6985, MT6989, MT6990, MT8168, MT8173, MT8195, MT8321, MT8385, MT8390, MT8666, MT8667, MT8673, MT8676, MT8678, MT8755, MT8765, MT8766, MT8768, MT8775, MT8781, MT8786, MT8788, MT8791T, MT8792, MT8796, MT8893v5
    Range: Android 13.0, 14.0 / OpenWrt 19.07, 21.02 / Yocto 2.6, 3.3 / RDKB 2022Q3
  • Mediatek/gnssllm-create
  • cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*
  • cpe:2.3:a:rdkcentral:rdk-b:2022q3:*:*:*:*:*:*:*
  • Google/Android2 versions
    cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    • cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
  • Openwrt/Openwrt2 versions
    cpe:2.3:o:openwrt:openwrt:19.07.0:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:openwrt:openwrt:19.07.0:-:*:*:*:*:*:*
    • cpe:2.3:o:openwrt:openwrt:21.02.0:-:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.