What is CVE-2026-20473?
This is a memory corruption vulnerability in the display component caused by a use-after-free error. It allows a malicious actor who has already gained System privilege to perform a local escalation of privilege without needing user interaction. Affected users should immediately apply the security update with Patch ID: ALPS11019722.
Azərbaycanca: Bu, display komponentində istifadə sonrası sərbəst qalma (use after free) səbəbindən yaranan yaddaş korrupsiyası zəifliyidir. Artıq Sistem imtiyazı əldə etmiş zərərli şəxs bu zəiflikdən lokal imtiyaz yüksəltmək üçün istifadə edə bilər. Təsirə məruz qalan istifadəçilər ALPS11019722 yamaq identifikatoru ilə təqdim edilmiş təhlükəsizlik yeniləməsini dərhal tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
What initial privilege must an attacker have to exploit CVE-2026-20473?
A malicious actor must already have gained System privilege to exploit this vulnerability.
Which security update should be applied to remediate CVE-2026-20473?
Affected users should immediately apply the security update with Patch ID: ALPS11019722.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.