What is CVE-2026-20476?
A vulnerability in the MediaTek CCCI component allows a local out-of-bounds read due to a missing bounds check. This could lead to a local denial of service with user execution privileges needed, without requiring user interaction. Users should apply patch ALPS10981532.
Azərbaycanca: MediaTek CCCI (Cellular Command Control Interface) komponentində sərhəd yoxlanışının olmaması səbəbindən lokal olaraq məlumat oxuma zəifliyi aşkarlanıb. Bu boşluq, istifadəçi icazələri ilə sistemin xidmətini dayandıra bilən (denial of service) təhlükə yaradır. İstifadəçilər ALPS10981532 yamasını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which MediaTek component was CVE-2026-20476 discovered?
The vulnerability was discovered in MediaTek's CCCI (Cellular Command Control Interface) component.
What patch has been assigned for CVE-2026-20476?
Users should apply patch ALPS10981532.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.