What is CVE-2026-20491?
An out-of-bounds write vulnerability exists in the 'med' component due to an incorrect bounds check, potentially leading to a local denial of service (DoS). It affects MediaTek platforms including MT6890, MT6990, and MT6988, requiring User execution privileges but no user interaction for exploitation. Applying the provided patches (ALPS10981478 or AUTO00851173) is recommended for affected devices.
Azərbaycanca: Med komponentində yanlış sərhəd yoxlaması səbəbindən "out of bounds write" zəifliyi mövcuddur ki, bu da lokal xidmət rəddinə (DoS) səbəb ola bilər. Zəiflik MT6890, MT6990, MT6988 kimi MediaTek platformalarına təsir edir və istismar üçün istifadəçi icazələri tələb olunsa da, qarşılıqlı əlaqə tələb etmir. Təsirlənən qurğular üçün təqdim olunan ALPS10981478 və ya AUTO00851173 yamaqlarının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which MediaTek platforms are affected by CVE-2026-20491?
This vulnerability affects the MT6890, MT6990, and MT6988 platforms.
Is user interaction required to exploit CVE-2026-20491?
No, user interaction is not required for exploitation, but User execution privileges are necessary.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.