What is CVE-2026-20464?
CVE-2026-20464 is a possible out of bounds write vulnerability in the HEVC decoder due to an integer overflow. If an attacker has already obtained System privilege, they could achieve remote escalation of privilege without user interaction. Affected devices should apply the patch identified by ALPS11104718.
Azərbaycanca: CVE-2026-20464 HEVC dekoderində tam ədəd daşması səbəbindən yaranan potensial `out of bounds write` zəifliyidir. Sistem imtiyazı əldə etmiş təcavüzkar bu zəiflikdən istifadə edərək uzaqdan imtiyaz artımı (`privilege escalation`) həyata keçirə bilər. Təsirə məruz qalan cihazlar üçün ALPS11104718 yamaq identifikatorlu yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
What initial privilege must an attacker have to successfully exploit CVE-2026-20464?
The attacker must have already obtained System privilege before exploiting this vulnerability.
How can I identify the necessary patch for CVE-2026-20464?
The update that addresses this vulnerability is identified by the patch ID ALPS11104718.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.