CVE-2023-20768 is a vulnerability in the 'ion' component, where a type confusion leads to a possible out-of-bounds read. The vulnerability can be exploited locally to escalate privileges to System level. No user interaction is required for exploitation. The issue is tracked as ALPS07559800 and patched under ALPS07560720.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a focused reachability study and proof-of-concept code for CVE-2023-20768 in MediaTek's Android ION allocator, tested against a Samsung Galaxy M32 (SM-M325F, Helio G80). It is not a weaponized exploit; instead it demonstrates that vulnerable kernel paths are reachable from userspace and explores whether the bug can be turned into a practical leak or crash. Structure: README.md is the main analysis write-up. Four C programs implement different trigger strategies: spoof.c targets the _ion_ioctl cache-sync path via ION_IOC_CUSTOM and crafted ion_sys_data; trigger.c attempts to invoke ion_drv_file_to_buffer through ION debug dump nodes; oom_trigger.c forces the same dump path through SysRq-triggered OOM; memcg_oom.c forces a memory-cgroup OOM to reach dump_header -> ion_mm_heap_memory_detail without debugfs. .gitignore is incidental. Main capability: spoof.c allocates a real ION buffer, obtains a valid handle, crafts raw 120-byte ion_sys_data, and issues ION_IOC_CUSTOM (cmd 0/system group, sys_cmd 0 cache sync) to drive execution into find_vma()/strcmp("ion") logic in _ion_ioctl. It fuzzes sync_type, size, and VA combinations, compares return codes, and scans returned buffers for leaked kernel pointers. This is a local kernel attack vector against /dev/ion, but the included results indicate the path is bounded by validation and did not yield a leak on the tested device. Secondary capability: trigger.c, oom_trigger.c, and memcg_oom.c try to reach the deeper vulnerable function ion_drv_file_to_buffer, where a name-based dmabuf check can lead to dereferencing file->private_data as though it were a dma_buf. These programs open /dev/ion so the process becomes an ION client, then hold many memfd descriptors named "dmabuf" (producing names like memfd:dmabuf) or a regular file named dmabuf, hoping the kernel's fd-walking dump logic will process them. The OOM-based variants attempt to invoke the dump path through kernel OOM handling rather than debugfs. Expected outcomes are kernel warnings in dmesg, evidence that the vulnerable function processed attacker-controlled fds, or a crash/info leak if the out-of-bounds read becomes observable. Overall conclusion from the repository content: the vulnerability is present and reachable on the tested build, including from unprivileged-triggerable OOM conditions, but the author did not achieve reliable exploitation. The code is best characterized as a local kernel PoC/research toolkit for reachability validation and trigger experimentation rather than a complete exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.