Vulnerability

CVE-2024-20021

In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation.

Impact

Severity (Manufact.)

MEDIUM

Severity (NIST)

N/A

Severity (Android)

N/A

Chipsets

17

Devices

245

Affected Hardware

NameAlso known asManufacturer
MT6768
Helio P65
MediaTek
MT6781
Helio G96
MediaTek
MT6833
Dimensity 6020
Dimensity 700
MediaTek
MT6873
Dimensity 800
MediaTek
MT6833
Dimensity 6080
Dimensity 810
MediaTek
MT6877
Dimensity 900
MediaTek
MT6877
Dimensity 920
MediaTek
MT6877
Dimensity 1080
Dimensity 7050 _T
MediaTek
MT6893
Dimensity 1200
MediaTek
MT6893
Dimensity 1300
Dimensity 8050 _T
MediaTek
17 of 17 row(s) shown.

Rows per page

Page 1 of 2

Timeline

Introduced (est):
Jul 1, 2019
Reported:
Unknown
Advisory Published:
May 6, 2024
CVE Published:
N/A
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter