CVE-2025-20765
MEDIUMDescription
In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linuxfoundation | yocto |
| android | |
| android | |
| android | |
| openwrt | openwrt |
| openwrt | openwrt |
| mediatek | mt2718 |
| mediatek | mt2737 |
| mediatek | mt6739 |
| mediatek | mt6761 |
| mediatek | mt6765 |
| mediatek | mt6768 |
| mediatek | mt6781 |
| mediatek | mt6789 |
| mediatek | mt6833 |
| mediatek | mt6835 |
| mediatek | mt6853 |
| mediatek | mt6855 |
| mediatek | mt6877 |
| mediatek | mt6878 |
| mediatek | mt6879 |
| mediatek | mt6880 |
| mediatek | mt6883 |
| mediatek | mt6885 |
| mediatek | mt6886 |
| mediatek | mt6889 |
| mediatek | mt6890 |
| mediatek | mt6893 |
| mediatek | mt6895 |
| mediatek | mt6897 |
| mediatek | mt6899 |
| mediatek | mt6980d |
| mediatek | mt6983 |
| mediatek | mt6985 |
| mediatek | mt6989 |
| mediatek | mt6990 |
| mediatek | mt6991 |
| mediatek | mt8113 |
| mediatek | mt8115 |
| mediatek | mt8139 |
| mediatek | mt8163 |
| mediatek | mt8168 |
| mediatek | mt8169 |
| mediatek | mt8183 |
| mediatek | mt8186 |
| mediatek | mt8188 |
| mediatek | mt8512 |
| mediatek | mt8516 |
| mediatek | mt8518 |
| mediatek | mt8519 |
| mediatek | mt8532 |
| mediatek | mt8676 |
| mediatek | mt8678 |
| mediatek | mt8695 |
| mediatek | mt8696 |
| mediatek | mt8698 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-20765? +
How severe is CVE-2025-20765? +
What products are affected by CVE-2025-20765? +
How do I check if I'm vulnerable to CVE-2025-20765? +
Related Vulnerabilities
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers …
Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of …
Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before …
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue …
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a …
go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if …