In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 03:16
Updated : 2026-08-28 21:28
NVD link : CVE-2026-20466
Mitre link : CVE-2026-20466
CVE.ORG link : CVE-2026-20466
JSON object : View
Products Affected
No product.
CWE
CWE-787
Out-of-bounds Write
