CVE-2025-20722 Details
Description
In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID: MSV-3798.
A vulnerability has been identified in the GNSS driver of certain MediaTek chipsets, where an integer overflow can lead to an out-of-bounds read. This issue could result in local information disclosure, but requires that the malicious actor has already obtained system privileges. The vulnerability arises from an incorrect bounds check, allowing for potential exploitation without user interaction.
Device OEMs have been notified of this vulnerability and the corresponding security patches are available. For further information, OEMs can contact their MediaTek representative.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://corp.mediatek.com/product-security-bulletin/October-2025 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rdkcentral rdk-b | 2024q1 |
CPE
Remediation
| |
| google android | 14.0 15.0 |
CPE
Remediation
| |
| openwrt openwrt | 21.02.0 - 23.05 |
CPE
Remediation
| |
| mediatek mt6835 | All versions |
CPE
Remediation
| |
| mediatek mt6878 | All versions |
CPE
Remediation
| |
| mediatek mt6886 | All versions |
CPE
Remediation
| |
| mediatek mt6897 | All versions |
CPE
Remediation
| |
| mediatek mt6899 | All versions |
CPE
Remediation
| |
| mediatek mt6980d | All versions |
CPE
Remediation
| |
| mediatek mt6985 | All versions |
CPE
Remediation
| |
| mediatek mt6989 | All versions |
CPE
Remediation
| |
| mediatek mt6990 | All versions |
CPE
Remediation
| |
| mediatek mt6991 | All versions |
CPE
Remediation
| |
| mediatek mt8676 | All versions |
CPE
Remediation
| |
| mediatek mt8678 | All versions |
CPE
Remediation
| |
| mediatek mt8775 | All versions |
CPE
Remediation
| |
| mediatek mt8791t | All versions |
CPE
Remediation
| |
| mediatek mt8796 | All versions |
CPE
Remediation
| |
| mediatek mt8873 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 15, 2025 | Initial Analysis | [email protected] |
| Oct 14, 2025 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | New CVE Received | [email protected] |