Description
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.
Published: 2026-08-03
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the ccci component of MediaTek chipsets, where a missing bounds check can trigger an out‑of‑bounds read (CWE‑125). This flaw can cause the system to become unresponsive in a local denial‑of‑service scenario, but it cannot be exploited remotely and requires the attacker to already hold System privilege. No user interaction is needed to trigger the failure, so any privileged process could inadvertently cause the crash.

Affected Systems

Affected systems are MediaTek chipsets running the ccci firmware component. No specific version information is listed in the advisory, so all implementations of ccci on MediaTek devices may potentially be vulnerable until patched.

Risk and Exploitability

The CVSS score is 4.4 and the EPSS score is less than 1%, but the flaw is not listed in the CISA KEV catalog, indicating that no publicly available exploitation code is known. Because the exploitation requires System privilege, the practical risk to unprivileged users is low. Nonetheless, once privilege is gained—for example, through a compromised application—an attacker could trigger the denial of service, causing service disruption to the affected device.

Generated by OpenCVE AI on August 5, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek patch identified as ALPS10981501 to update the ccci component.
  • Ensure that all firmware images deployed to devices contain the updated ccci component.
  • Restrict System‑level privileges for applications and services to reduce the impact scope if a vulnerability is later discovered.

Generated by OpenCVE AI on August 5, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt6813
Mediatek mt6813 Firmware
Mediatek mt6982vb
Mediatek mt6982vb Firmware
Mediatek mt6986
Mediatek mt6986 Firmware
Mediatek mt6986d
Mediatek mt6986d Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
CPEs cpe:2.3:h:mediatek:mt6813:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6982vb:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6986:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6986d:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6813_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6982vb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6986_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6986d_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt6813
Mediatek mt6813 Firmware
Mediatek mt6982vb
Mediatek mt6982vb Firmware
Mediatek mt6986
Mediatek mt6986 Firmware
Mediatek mt6986d
Mediatek mt6986d Firmware
Mediatek mt6988
Mediatek mt6988 Firmware

Wed, 05 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Out‑of‑Bounds Read in MediaTek CCCI Component

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Out‑of‑Bounds Read in MediaTek CCCI Component

Mon, 03 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.
Weaknesses CWE-125
References

Subscriptions

Mediatek Mt6813 Mt6813 Firmware Mt6982vb Mt6982vb Firmware Mt6986 Mt6986 Firmware Mt6986d Mt6986d Firmware Mt6988 Mt6988 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T18:55:15.763Z

Reserved: 2025-11-03T01:30:59.023Z

Link: CVE-2026-20490

cve-icon Vulnrichment

Updated: 2026-08-03T18:54:56.117Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:44.110

Modified: 2026-08-19T15:08:04.757

Link: CVE-2026-20490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T05:00:11Z

Weaknesses