In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
History

Wed, 05 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Local Denial of Service in MediaTek Chipsets

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Local Denial of Service in MediaTek Chipsets

Mon, 03 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published: 2026-08-03T02:05:57.128Z

Updated: 2026-08-03T18:58:11.761Z

Reserved: 2025-11-03T01:30:59.025Z

Link: CVE-2026-20491

cve-icon Vulnrichment

Updated: 2026-08-03T18:58:08.136Z

cve-icon NVD

Status : Received

Published: 2026-08-03T03:16:44.220

Modified: 2026-08-03T19:16:45.910

Link: CVE-2026-20491

cve-icon Redhat

No data.