CVE-2023-20747
CVE-2023-20747 is a medium-severity vulnerability in Linuxfoundation Iot-yocto with a CVSS 3.x base score of 4.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-843.
Key facts
- Severity: Medium (CVSS 3.x base score 4.4)
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-843
- Affected product: Linuxfoundation Iot-yocto
- Published:
- Last modified:
Description
In vcu, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519121.
Frequently asked questions
- What is CVE-2023-20747?
- In vcu, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519121.
- How severe is CVE-2023-20747?
- CVE-2023-20747 has a CVSS 3.x base score of 4.4, rated medium severity. It is exploitable over local access with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2023-20747 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-20747?
- CVE-2023-20747 primarily affects Linuxfoundation Iot-yocto. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-20747?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-20747 published?
- CVE-2023-20747 was published on 2023-06-06 and last updated on 2026-06-17.
References
Affected products (4)
- cpe:2.3:a:linuxfoundation:iot-yocto:22.2:*:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
More vulnerabilities in Linuxfoundation Iot-yocto
- CVE-2023-20746 — Medium (CVSS 6.7): In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of…
- CVE-2023-20745 — Medium (CVSS 6.7): In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of…
- CVE-2023-20744 — Medium (CVSS 6.7): In vcu, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with…
- CVE-2023-20743 — Medium (CVSS 6.7): In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of…
- CVE-2023-20740 — Medium (CVSS 6.7): In vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege…
- CVE-2023-20738 — Medium (CVSS 6.7): In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of…
All CVEs affecting Linuxfoundation Iot-yocto →
Other CWE-843 vulnerabilities
- CVE-2021-33970 — Critical (CVSS 10.0): Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.
- CVE-2010-2299 — Critical (CVSS 10.0): The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not…
- CVE-2023-22579 — Critical (CVSS 9.9): Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
- CVE-2026-16919 — Critical (CVSS 9.8): IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper…
- CVE-2026-71558 — Critical (CVSS 9.8): Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from…
- CVE-2026-64727 — Critical (CVSS 9.8): A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6.…