Description
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.
Published: 2026-08-03
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the Audio HAL caused by a heap buffer overflow. It can be triggered locally without remote access and does not require user interaction beyond normal usage. An attacker with user execution privileges can corrupt memory and crash the audio subsystem, leading to a denial of service. The weakness is categorized as an out‑of‑bounds write (CWE‑787).

Affected Systems

Affected hardware includes MediaTek chipsets in the MT6880, MT6890, MT6988, and MT6990 families, as well as the MT2735 and MT2737 models. The vulnerability is present in the default firmware and software running on these devices.

Risk and Exploitability

An EPSS score of < 1% indicates a low exploitation probability, and the issue is not listed in the CISA KEV catalog. The CVSS score of 5.5 places the vulnerability in the medium severity range. The vulnerability is local and relies on user‑level execution, which is common on most devices. Because it does not require user interaction beyond regular operation, any user could trigger it. The potential impact is a service crash, which can disrupt device functionality. Given the lack of public exploitation data, the immediate risk is moderate, but it remains important to address the flaw promptly.

Generated by OpenCVE AI on August 4, 2026 at 21:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch ALPS10981454 for MT6880, MT6890, MT6988, MT6990 or AUTO00851293 for MT2735, MT2737.
  • Restart the device to ensure the patched audio driver is loaded.
  • Verify that the audio service operates correctly without crashes after the update.

Generated by OpenCVE AI on August 4, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt2737:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2735_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2737_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6880_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6990_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware

Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Audio HAL Heap Buffer Overflow Leading to Local Denial of Service

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Audio HAL Heap Buffer Overflow Leading to Local Denial of Service

Mon, 03 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.
Weaknesses CWE-787
References

Subscriptions

Mediatek Mt2735 Mt2735 Firmware Mt2737 Mt2737 Firmware Mt6880 Mt6880 Firmware Mt6890 Mt6890 Firmware Mt6988 Mt6988 Firmware Mt6990 Mt6990 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T19:08:03.304Z

Reserved: 2025-11-03T01:30:59.021Z

Link: CVE-2026-20478

cve-icon Vulnrichment

Updated: 2026-08-03T19:07:59.851Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:42.867

Modified: 2026-08-20T14:58:36.667

Link: CVE-2026-20478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:00:07Z

Weaknesses