VYPR
Medium severity6.7NVD Advisory· Published Jan 6, 2025· Updated Jun 17, 2026

CVE-2024-20140

CVE-2024-20140

Description

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09270402; Issue ID: MSV-2020.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:yocto:5.0:*:*:*:*:*:*:*
  • Google/Android4 versions
    cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
    • cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
    • cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
    • cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
  • Mediatek/powerllm-fuzzy
  • MediaTek, Inc./MT6739, MT6761, MT6768, MT6781, MT6833, MT6853, MT6877, MT6885, MT6893, MT8518S, MT8532v5
    Range: Android 12.0, 13.0, 14.0, 15.0 / Yocto 3.3, 4.0, 5.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.