Description
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.
Published: 2026-08-03
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write caused by a missing bounds check in the MediaTek Decoding Algorithm, which could allow a local attacker with physical access to trigger a failure resulting in denial of service. No additional privileges or user interaction are required. This weakness falls under CWE‑787.

Affected Systems

Affected are MediaTek chipsets, including MT6880, MT6890, MT6990, MT6988, MT6986, MT6813, MT2735, and MT2737, as identified by the vendor's patch IDs. System administrators should check whether their devices use these components.

Risk and Exploitability

Because the flaw requires only physical presence to trigger, the risk remains significant for environments where attackers can touch the hardware. The EPSS score of < 1% indicates a very low probability of exploitation, and the CVSS score of 4.6 denotes a low‑severity vulnerability. The vulnerability is not listed in KEV, and the lack of a user interaction barrier suggests that the exploit can be performed with minimal effort by anyone who can gain access to the device.

Generated by OpenCVE AI on August 4, 2026 at 10:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek patch ALPS10991588 to the affected MT6880, MT6890, MT6990, MT6988, MT6986, and MT6813 chipsets.
  • Apply the MediaTek patch AUTO00851171 to the MT2735 and MT2737 chipsets.
  • Restrict physical access to the devices to prevent tampering or local exploitation; ensure that only authorized personnel can interact with the hardware.

Generated by OpenCVE AI on August 4, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Out-of-Bounds Write in MediaTek Decoding Algorithm

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.
Weaknesses CWE-787
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T19:04:40.680Z

Reserved: 2025-11-03T01:30:59.015Z

Link: CVE-2026-20471

cve-icon Vulnrichment

Updated: 2026-08-03T19:04:30.767Z

cve-icon NVD

Status : Received

Published: 2026-08-03T03:16:42.060

Modified: 2026-08-03T20:17:19.100

Link: CVE-2026-20471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:00:07Z

Weaknesses