Impact
The flaw is an out‑of‑bounds write that results from a heap buffer overflow in the Audio Hardware Abstraction Layer. Attackers possessing local user privileges can trigger the overwrite without any user interaction, causing the audio subsystem to crash and leading to a local denial of service. The issue is classified as CWE‑122.
Affected Systems
MediaTek Inc. chipsets are affected: MT6880, MT6890, MT6980D, MT6988, MT6990, MT2735, and MT3737. For the former group of chipsets, the vendor has released patch ALPS10960023, and for MT2735 and MT3737 the patch is AUTO00851189. The vulnerability is recorded under issue ID MSV‑7586.
Risk and Exploitability
With a CVSS score of 5.5 and an EPSS score of less than 1%, the flaw is not listed in the CISA KEV catalog, but the ability for any local user to exploit a heap overflow without prior interaction increases its potential impact. Malicious software running with user privileges can repeatedly crash the audio services, causing availability disruptions in critical environments. The lack of hardening and the local nature of the attack suggest a moderate to high risk until a patch is applied.
OpenCVE Enrichment