CVE-2025-20648
MEDIUMDescription
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.
Is your site exposed to CVE-2025-20648?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| android | |
| android | |
| android | |
| mediatek | mt2718 |
| mediatek | mt6879 |
| mediatek | mt6989 |
| mediatek | mt8196 |
| mediatek | mt8370 |
| mediatek | mt8390 |
| mediatek | mt8395 |
| mediatek | mt8673 |
| mediatek | mt8678 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-20648? +
How severe is CVE-2025-20648? +
What products are affected by CVE-2025-20648? +
How do I check if I'm vulnerable to CVE-2025-20648? +
Related Vulnerabilities
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() …
Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: …
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a …
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial …
An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system …
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read …