CVE-2024-25986
Last modified
CVE-2024-25986 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In ppmp_unprotect_buf of drm_fw.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
In ppmp_unprotect_buf of drm_fw.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 13.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-25986?
How severe is CVE-2024-25986?
How do I fix CVE-2024-25986?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25980Separate Groups mode restrictions were not honored in the H5…5.3
- CVE-2024-25981Separate Groups mode restrictions were not honored when perf…5.3
- CVE-2024-25982The link to update all installed language packs did not incl…8.8
- CVE-2024-25983Insufficient checks in a web service made it possible to add…5.3
- CVE-2024-25984In dumpBatteryDefend of dump_power.cpp, there is a possible …6.2
- CVE-2024-25985In bigo_unlocked_ioctl of bigo.c, there is a possible UAF du…8.4
- CVE-2024-25987In pt_sysctl_command of pt.c, there is a possible out of bou…6.7
- CVE-2024-25988In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is…8.4
- CVE-2024-25989In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a po…5.9
- CVE-2024-2599File upload restriction evasion vulnerability in AMSS++ vers…8.8
- CVE-2024-25990In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pkt…6.4
- CVE-2024-25991In acpm_tmu_ipc_handler of tmu_plugin.c, there is a possible…3.3
Are you affected by CVE-2024-25986?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
