CVE-2025-20722
MEDIUMDescription
In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID: MSV-3798.
Is your site exposed to CVE-2025-20722?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| rdkcentral | rdk-b |
| android | |
| android | |
| openwrt | openwrt |
| openwrt | openwrt |
| mediatek | mt6835 |
| mediatek | mt6878 |
| mediatek | mt6886 |
| mediatek | mt6897 |
| mediatek | mt6899 |
| mediatek | mt6980d |
| mediatek | mt6985 |
| mediatek | mt6989 |
| mediatek | mt6990 |
| mediatek | mt6991 |
| mediatek | mt8676 |
| mediatek | mt8678 |
| mediatek | mt8775 |
| mediatek | mt8791t |
| mediatek | mt8796 |
| mediatek | mt8873 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-20722? +
How severe is CVE-2025-20722? +
What products are affected by CVE-2025-20722? +
How do I check if I'm vulnerable to CVE-2025-20722? +
Related Vulnerabilities
Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.
z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when …
If a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of …
Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability is associated with program files lua_struct.C. This issue …
An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers …
KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t …