What is CVE-2026-20480?
A heap buffer overflow vulnerability in Audio HAL leads to a possible out-of-bounds write, affecting MT6880, MT6890, MT6980D, MT6988, MT6990 chipsets. This may result in a local denial of service with user execution privileges required and no user interaction needed; apply patch ALPS10960023.
Azərbaycanca: Audio HAL komponentində heap buffer overflow səbəbindən "out of bounds write" zəifliyi aşkarlanıb. Bu, MT6880, MT6890, MT6980D, MT6988, MT6990 prosessorlarına təsir edir və lokal xidmət inkarına (denial of service) səbəb ola bilər. İstismar üçün istifadəçi icazələri tələb olunur, lakin istifadəçi qarşılıqlı əlaqəsi lazım deyil; ALPS10960023 yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which MediaTek chipsets are affected by CVE-2026-20480?
This vulnerability affects MT6880, MT6890, MT6980D, MT6988, and MT6990 chipsets.
What are the exploitation requirements for CVE-2026-20480?
User execution privileges are required, but no user interaction is needed for exploitation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.