n the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
| Link | Resource |
|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-en | Vendor Advisory |
| https://source.android.com/security/bulletin/2020-03-01 | Vendor Advisory |
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-en | Vendor Advisory |
| https://source.android.com/security/bulletin/2020-03-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0069 | Third Party Advisory US Government Resource |
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
Configuration 15 (hide)
| AND |
|
Configuration 16 (hide)
| AND |
|
Configuration 17 (hide)
| AND |
|
Configuration 18 (hide)
| AND |
|
Configuration 19 (hide)
| AND |
|
Configuration 20 (hide)
| AND |
|
Configuration 21 (hide)
| AND |
|
Configuration 22 (hide)
| AND |
|
Configuration 23 (hide)
| AND |
|
Configuration 24 (hide)
| AND |
|
Configuration 25 (hide)
| AND |
|
Configuration 26 (hide)
| AND |
|
Configuration 27 (hide)
| AND |
|
Configuration 28 (hide)
| AND |
|
Configuration 29 (hide)
| AND |
|
Configuration 30 (hide)
| AND |
|
Configuration 31 (hide)
| AND |
|
Configuration 32 (hide)
| AND |
|
Configuration 33 (hide)
| AND |
|
Configuration 34 (hide)
| AND |
|
Configuration 35 (hide)
| AND |
|
Configuration 36 (hide)
| AND |
|
Configuration 37 (hide)
| AND |
|
Configuration 38 (hide)
| AND |
|
Configuration 39 (hide)
| AND |
|
23 Oct 2025, 14:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0069 - Third Party Advisory, US Government Resource |
22 Oct 2025, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 04:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-en - Vendor Advisory | |
| References | () https://source.android.com/security/bulletin/2020-03-01 - Vendor Advisory |
25 Jul 2024, 14:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Huawei columbia-l29d
Huawei columbia-al10b Firmware Huawei Huawei yale-al00a Huawei columbia-al10b Huawei nova 3 Huawei cornell-al00a Huawei dura-al00a Firmware Huawei honor View 20 Huawei honor 8a Firmware Huawei nova 4 Firmware Huawei katyusha-al00a Huawei tony-al00b Huawei cornell-tl10b Huawei paris-l29b Firmware Huawei tony-tl00b Huawei sydney-al00 Huawei columbia-tl00b Huawei columbia-l29d Firmware Huawei honor 20 Pro Firmware Huawei princeton-al10b Firmware Huawei tony-al00b Firmware Huawei sydney-tl00 Firmware Huawei yale-al00a Firmware Huawei princeton-al10b Huawei honor View 20 Firmware Huawei yalep-al10b Huawei yale-l21a Firmware Huawei jakarta-al00a Huawei berkeley-l09 Huawei madrid-al00a Firmware Huawei columbia-tl00b Firmware Huawei sydney-tl00 Huawei dura-al00a Huawei y6 2019 Firmware Huawei jakarta-al00a Firmware Huawei sydneym-al00 Firmware Huawei columbia-tl00d Huawei sydney-al00 Firmware Huawei nova 4 Huawei cornell-al00a Firmware Huawei honor 20 Pro Huawei tony-tl00b Firmware Huawei paris-l29b Huawei katyusha-al00a Firmware Huawei yalep-al10b Firmware Huawei madrid-al00a Huawei y6 2019 Huawei nova 3 Firmware Huawei yale-l21a Huawei katyusha-al10a Huawei honor 8a Huawei katyusha-al10a Firmware Huawei berkeley-l09 Firmware Huawei sydneym-al00 Huawei columbia-tl00d Firmware Huawei cornell-tl10b Firmware |
|
| References | () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-mtk-en - Vendor Advisory | |
| CPE | cpe:2.3:o:huawei:columbia-al10b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:berkeley-l09:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:columbia-l29d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:cornell-al00a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:honor_20_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:columbia-l29d:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:paris-l29b:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:princeton-al10b:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:paris-l29b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:katyusha-al10a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:cornell-tl10b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:sydney-al00:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:sydney-tl00:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:columbia-al10b:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:columbia-tl00d:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:katyusha-al10a:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:nova_4_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:honor_8a_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:madrid-al00a:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:sydneym-al00_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:tony-tl00b:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:tony-al00b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:yalep-al10b:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:katyusha-al00a_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:honor_20_pro:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:princeton-al10b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:cornell-al00a:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:madrid-al00a_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:katyusha-al00a:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:honor_8a:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:y6_2019_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:nova_3:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:honor_view_20_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:dura-al00a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:sydney-al00_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:sydney-tl00_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:tony-al00b:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:yale-al00a:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:yalep-al10b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:nova_4:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:nova_3_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:y6_2019:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:tony-tl00b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:yale-l21a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:columbia-tl00b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:yale-al00a_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:jakarta-al00a:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:dura-al00a:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:columbia-tl00b:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:sydneym-al00:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:cornell-tl10b:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:yale-l21a:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:jakarta-al00a_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:huawei:honor_view_20:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:berkeley-l09_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:huawei:columbia-tl00d_firmware:*:*:*:*:*:*:*:* |
Published : 2020-03-10 20:15
Updated : 2025-10-23 14:52
NVD link : CVE-2020-0069
Mitre link : CVE-2020-0069
CVE.ORG link : CVE-2020-0069
JSON object : View
- tony-al00b_firmware
- columbia-l29d_firmware
- katyusha-al10a
- columbia-tl00d
- cornell-tl10b_firmware
- nova_4_firmware
- katyusha-al00a
- columbia-al10b
- paris-l29b_firmware
- dura-al00a_firmware
- princeton-al10b_firmware
- tony-tl00b_firmware
- yale-al00a_firmware
- yalep-al10b
- honor_view_20_firmware
- yalep-al10b_firmware
- honor_view_20
- yale-al00a
- jakarta-al00a_firmware
- madrid-al00a
- sydneym-al00_firmware
- y6_2019
- sydney-tl00_firmware
- paris-l29b
- jakarta-al00a
- sydney-al00
- cornell-tl10b
- honor_8a
- dura-al00a
- tony-al00b
- yale-l21a
- nova_3_firmware
- princeton-al10b
- nova_4
- madrid-al00a_firmware
- nova_3
- yale-l21a_firmware
- katyusha-al10a_firmware
- honor_20_pro_firmware
- berkeley-l09_firmware
- y6_2019_firmware
- columbia-al10b_firmware
- columbia-l29d
- columbia-tl00b_firmware
- columbia-tl00d_firmware
- cornell-al00a
- sydney-tl00
- berkeley-l09
- columbia-tl00b
- honor_20_pro
- cornell-al00a_firmware
- sydneym-al00
- sydney-al00_firmware
- katyusha-al00a_firmware
- tony-tl00b
- honor_8a_firmware
Out-of-bounds Write