CVE Vulnerabilities

CVE-2025-20638

Use of Uninitialized Variable

Published: Feb 03, 2025 | Modified: Feb 03, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291449; Issue ID: MSV-2066.

Weakness

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Affected Software

Name Vendor Start Version End Version
Android Google 12.0 (including) 12.0 (including)
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)
Android Google 15.0 (including) 15.0 (including)

Potential Mitigations

References