Linuxfoundation
Linuxfoundation Yocto: vulnerabilidades y CVE
Linuxfoundation Yocto tiene 114 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE114
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-61611 | Alta (7.5) | 0.56% | — | 9 mar 2026 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.. |
| CVE-2026-20435 | Media (4.6) | 0.12% | — | 2 mar 2026 | In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution… |
| CVE-2025-20765 | Media (4.7) | 0.07% | — | 2 dic 2025 | In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for… |
| CVE-2025-20747 | Media (6.7) | 0.08% | — | 4 nov 2025 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20746 | Media (6.7) | 0.08% | — | 4 nov 2025 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20730 | Media (6.7) | 0.07% | — | 4 nov 2025 | In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20705 | Alta (7.8) | 0.09% | — | 1 sept 2025 | In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2025-20696 | Media (6.8) | 0.12% | — | 4 ago 2025 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges… |
| CVE-2025-20693 | Media (6.5) | 0.14% | — | 8 jul 2025 | In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User… |
| CVE-2025-20656 | Media (6.8) | 0.12% | — | 7 abr 2025 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges… |
| CVE-2025-20651 | Media (4.1) | 0.09% | — | 3 mar 2025 | In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges… |
| CVE-2025-20650 | Media (6.8) | 0.11% | — | 3 mar 2025 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges… |
| CVE-2025-20635 | Media (6.6) | 0.10% | — | 3 feb 2025 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution… |
| CVE-2024-20147 | Media (5.3) | 0.21% | — | 3 feb 2025 | In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2024-20153 | Alta (7.5) | 0.32% | — | 6 ene 2025 | In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not… |
| CVE-2024-20152 | Media (4.4) | 0.09% | — | 6 ene 2025 | In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction… |
| CVE-2024-20148 | Crítica (9.8) | 0.26% | — | 6 ene 2025 | In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is… |
| CVE-2024-20146 | Alta (8.1) | 0.14% | — | 6 ene 2025 | In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction… |
| CVE-2024-20145 | Media (6.6) | 0.11% | — | 6 ene 2025 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution… |
| CVE-2024-20144 | Media (6.6) | 0.11% | — | 6 ene 2025 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution… |
| CVE-2024-20143 | Media (6.6) | 0.11% | — | 6 ene 2025 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution… |
| CVE-2024-20140 | Media (6.7) | 0.08% | — | 6 ene 2025 | In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2024-20139 | Media (6.5) | 0.12% | — | 2 dic 2024 | In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction… |
| CVE-2024-20107 | Media (6.2) | 0.10% | — | 4 nov 2024 | In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2024-20104 | Alta (8.4) | 0.09% | — | 4 nov 2024 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.… |
| CVE-2024-20099 | Media (6.7) | 0.08% | — | 7 oct 2024 | In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2024-20098 | Media (6.7) | 0.08% | — | 7 oct 2024 | In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2024-20089 | Alta (7.5) | 0.31% | — | 2 sept 2024 | In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2024-20085 | Media (4.4) | 0.10% | — | 2 sept 2024 | In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2024-20084 | Media (4.4) | 0.10% | — | 2 sept 2024 | In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.… |