PT-2020-6503 · Google+1 · Android Kernel+1

Published

2020-03-01

·

Updated

2025-10-23

·

CVE-2020-0069

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to the Mediatek Command Queue driver in Android operating systems, specifically a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Millions of Android devices are potentially affected.
Recommendations For Android kernel, consider applying the security patch from the Android Security bulletin to fix the issue. As a temporary workaround, restrict access to the ioctl handlers of the Mediatek Command Queue driver to minimize the risk of exploitation. Avoid using the vulnerable Mediatek Command Queue driver until the issue is resolved.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2021-05598
CVE-2020-0069

Affected Products

Android Kernel
Mediatek Command Queue Driver