CVE Vulnerabilities

CVE-2024-20021

Improper Privilege Management

Published: May 06, 2024 | Modified: Apr 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle12.0 (including)12.0 (including)
AndroidGoogle13.0 (including)13.0 (including)
AndroidGoogle14.0 (including)14.0 (including)

Potential Mitigations

References