In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.
References
| Link | Resource |
|---|---|
| https://www.mediatek.com/product-security-bulletin/August-2026 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
No history.
Information
Published : 2026-08-03 03:16
Updated : 2026-08-20 14:58
NVD link : CVE-2026-20478
Mitre link : CVE-2026-20478
CVE.ORG link : CVE-2026-20478
JSON object : View
Products Affected
mediatek
- mt2735_firmware
- mt6988_firmware
- mt2737
- mt6880
- mt6890_firmware
- mt6988
- mt2737_firmware
- mt6990
- mt6890
- mt2735
- mt6990_firmware
- mt6880_firmware
CWE
CWE-787
Out-of-bounds Write
