CVE Vulnerabilities

CVE-2025-20694

Buffer Underwrite ('Buffer Underflow')

Published: Jul 08, 2025 | Modified: Jul 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09752821; Issue ID: MSV-3342.

Weakness

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software

Name Vendor Start Version End Version
Software_development_kit Mediatek * 3.7 (including)
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)
Android Google 15.0 (including) 15.0 (including)
Openwrt Openwrt 21.02.0 (including) 21.02.0 (including)
Openwrt Openwrt 23.05 (including) 23.05 (including)

Potential Mitigations

References