CVE Vulnerabilities

CVE-2025-20765

Double Free

Published: Dec 02, 2025 | Modified: Dec 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833.

Weakness

The product calls free() twice on the same memory address.

Affected Software

Name Vendor Start Version End Version
Yocto Linuxfoundation 4.0 (including) 4.0 (including)
Android Google 14.0 (including) 14.0 (including)
Android Google 15.0 (including) 15.0 (including)
Android Google 16.0 (including) 16.0 (including)
Openwrt Openwrt 21.02.0 (including) 21.02.0 (including)
Openwrt Openwrt 23.05.0 (including) 23.05.0 (including)

Potential Mitigations

References