Description
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
Published: 2026-08-03
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write caused by an incorrect bounds check in MediaTek’s firmware. An attacker with local execution privileges could trigger the write, resulting in a denial of service on the affected chipsets. The flaw does not require user interaction beyond the privilege level needed to execute code.

Affected Systems

MediaTek chipsets are impacted: models MT6890, MT6990, and MT6988 are fixed by patch ALPS10981478, while MT2735 and MT2737 are resolved by patch AUTO00851173. No specific firmware or version range is listed, but the referenced patch IDs apply to those device families.

Risk and Exploitability

Risk assessment shows an EPSS score of < 1% and no KEV listing; the CVSS score is 5.5, indicating medium severity. Because the exploit requires local execution privileges and no remote triggering, the likelihood of exploitation is low, but local attackers could cause a denial of service interrupting device operation. No publicly known exploits exist, so the current risk remains moderate until the patch is applied.

Generated by OpenCVE AI on August 5, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the firmware update that includes patch ALPS10981478 on all devices using MT6890, MT6990 or MT6988.
  • Install the firmware update that includes patch AUTO00851173 on all devices using MT2735 or MT2737.
  • If a firmware update cannot be applied immediately, disable or limit functionality that relies on the affected component to mitigate potential service interruptions.

Generated by OpenCVE AI on August 5, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt2737:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2735_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2737_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6990_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware

Wed, 05 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Local Denial of Service in MediaTek Chipsets

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Local Denial of Service in MediaTek Chipsets

Mon, 03 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
Weaknesses CWE-787
References

Subscriptions

Mediatek Mt2735 Mt2735 Firmware Mt2737 Mt2737 Firmware Mt6890 Mt6890 Firmware Mt6988 Mt6988 Firmware Mt6990 Mt6990 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T18:58:11.761Z

Reserved: 2025-11-03T01:30:59.025Z

Link: CVE-2026-20491

cve-icon Vulnrichment

Updated: 2026-08-03T18:58:08.136Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:44.220

Modified: 2026-08-19T15:08:11.660

Link: CVE-2026-20491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T05:00:11Z

Weaknesses