MediaTekCVE-2026-20471
MediaTek chipset: out-of-bounds write
Medium4.6CVE-2026-20471 · Published Aug 3, 2026 · updated Aug 28, 2026
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MediaTek chipset Product | <= MT2735 | No fix yet |
| <= MT2737 | No fix yet | |
| <= MT6813 | No fix yet | |
| <= MT6880 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-787
More MediaTek advisories
All MediaTek| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 3 | MediaTek chipset: privilege escalation | Medium6.0 | No fix yet |
| Aug 3 | MediaTek chipset: out-of-bounds read | Medium4.4 | No fix yet |
| Aug 3 | MediaTek chipset: out-of-bounds write | Medium5.5 | No fix yet |
| Aug 3 | MediaTek chipset: race condition | Medium5.5 | No fix yet |
| Aug 3 | MediaTek chipset: out-of-bounds write | Medium4.4 | No fix yet |
| Aug 3 | MediaTek chipset: out-of-bounds read | Medium5.5 | No fix yet |