8.4

CVE-2026-20524

In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mediatek ≫ Mt6899 Firmware Version -
   Mediatek ≫ Mt6899 Version -
Mediatek ≫ Mt6993 Firmware Version -
   Mediatek ≫ Mt6993 Version -
Mediatek ≫ Mt8668 Firmware Version -
   Mediatek ≫ Mt8668 Version -
Mediatek ≫ Mt8781 Firmware Version -
   Mediatek ≫ Mt8781 Version -
Mediatek ≫ Mt8793 Firmware Version -
   Mediatek ≫ Mt8793 Version -
Mediatek ≫ Mt8910 Firmware Version -
   Mediatek ≫ Mt8910 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input

The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.

https://www.mediatek.com/product-security-bulletin/October-2026
Vendor Advisory