CVE-2025-20788
BaseFortify
Publication date: 2025-12-02
Last updated on: 2025-12-03
Assigner: MediaTek, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 15.0 | |
| mediatek | mt6991 | * |
| mediatek | mt8196 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1262 | The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the GPU pdma component where a missing permission check can cause memory corruption. Exploiting this flaw requires user interaction and does not grant any additional execution privileges.
How can this vulnerability impact me? :
The vulnerability can lead to a local denial of service on the affected system, potentially causing the system or application to crash or become unresponsive. No further execution privileges can be gained through this vulnerability.
What immediate steps should I take to mitigate this vulnerability?
Apply the patch identified as ALPS10117735 provided by the vendor to fix the missing permission check in GPU pdma. Additionally, limit user interaction with the affected component until the patch is applied to reduce the risk of exploitation.