What is CVE-2026-20478?
A critical vulnerability in the Audio HAL of MediaTek chipsets (MT6880, MT6890, MT6988, MT6990) allows an out-of-bounds write due to a heap buffer overflow, leading to local denial of service. Exploitation requires user execution privileges but no user interaction, and immediate patching with ALPS10981454 and AUTO00851293 is necessary for affected devices.
Azərbaycanca: MediaTek çipsetlərində (MT6880, MT6890, MT6988, MT6990) Audio HAL komponentində aşkarlanan kritik boşluq, heap bufer daşması nəticəsində yaddaşa icazəsiz yazmağa imkan verir. Bu, lokal denial of service (DoS) vəziyyətinə səbəb ola bilər, istismar üçün istifadəçi icazələri tələb olunur, lakin qarşılıqlı əlaqəyə ehtiyac yoxdur. Təsirlənmiş cihazlar üçün təcili olaraq ALPS10981454 və AUTO00851293 yamaqları tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which MediaTek chipset models are affected by the Audio HAL vulnerability (CVE-2026-20478)?
The vulnerability affects MediaTek's MT6880, MT6890, MT6988, and MT6990 chipsets.
Which patch identifiers must be applied to remediate CVE-2026-20478?
The ALPS10981454 and AUTO00851293 patches must be applied immediately for affected devices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.