What is CVE-2026-20477?
This vulnerability is an out of bounds write in the 'display' component due to a missing bounds check. It could allow local escalation of privilege if an attacker has already achieved System access, requiring no user interaction for exploitation. Affected devices should immediately apply the security patch (Patch ID: ALPS11009963).
Azərbaycanca: Bu boşluq 'display' komponentində sərhəd yoxlanışının olmaması səbəbindən yaranan out of bounds write zəifliyidir. Əgər təcavüzkar artıq Sistem imtiyazı əldə edibsə, bu zəiflik lokal imtiyaz yüksəltməyə (local escalation of privilege) səbəb ola bilər. İstismar üçün istifadəçi qarşılıqlı əlaqəsi tələb olunmadığı üçün, təsirə məruz qalan qurğularda dərhal təhlükəsizlik yaması tətbiq edilməlidir (Patch ID: ALPS11009963).
Related CVEs
link basis: same weakness class CWE-787
FAQ2
In which component was CVE-2026-20477 discovered, and does exploitation require user interaction?
The vulnerability was discovered in the 'display' component. Exploitation requires no user interaction.
If this out of bounds write vulnerability is successfully exploited, what could it lead to?
It could lead to local escalation of privilege if the attacker has already achieved System access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.