Description
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.
Published: 2026-08-03
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an out‑of‑bounds write that results from a heap buffer overflow in the Audio Hardware Abstraction Layer. Attackers possessing local user privileges can trigger the overwrite without any user interaction, causing the audio subsystem to crash and leading to a local denial of service. The issue is classified as CWE‑122.

Affected Systems

MediaTek Inc. chipsets are affected: MT6880, MT6890, MT6980D, MT6988, MT6990, MT2735, and MT3737. For the former group of chipsets, the vendor has released patch ALPS10960023, and for MT2735 and MT3737 the patch is AUTO00851189. The vulnerability is recorded under issue ID MSV‑7586.

Risk and Exploitability

With a CVSS score of 5.5 and an EPSS score of less than 1%, the flaw is not listed in the CISA KEV catalog, but the ability for any local user to exploit a heap overflow without prior interaction increases its potential impact. Malicious software running with user privileges can repeatedly crash the audio services, causing availability disruptions in critical environments. The lack of hardening and the local nature of the attack suggest a moderate to high risk until a patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 10:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply patch ALPS10960023 to MT6880, MT6890, MT6980D, MT6988, and MT6990, and patch AUTO00851189 to MT2735 and MT3737 to eliminate the buffer overflow.
  • Restart the audio service after applying the patch so that the updated code is in use.
  • If a firmware update cannot be performed immediately, temporarily disable or limit usage of the affected Audio HAL features until the vendor patch is installed.

Generated by OpenCVE AI on August 4, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6980d
Mediatek mt6980d Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt2737:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980d:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2735_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2737_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6880_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6980d_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6990_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6980d
Mediatek mt6980d Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware

Tue, 04 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Audio HAL Heap Buffer Overflow Causes Local Denial of Service

Mon, 03 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.
Weaknesses CWE-122
References

Subscriptions

Mediatek Mt2735 Mt2735 Firmware Mt2737 Mt2737 Firmware Mt6880 Mt6880 Firmware Mt6890 Mt6890 Firmware Mt6980d Mt6980d Firmware Mt6988 Mt6988 Firmware Mt6990 Mt6990 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T19:02:18.404Z

Reserved: 2025-11-03T01:30:59.021Z

Link: CVE-2026-20480

cve-icon Vulnrichment

Updated: 2026-08-03T19:02:15.181Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:43.097

Modified: 2026-08-19T17:16:12.410

Link: CVE-2026-20480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:00:07Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow