Description
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.
Published: 2026-08-03
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a race condition in the Audio HAL component that can render the system unresponsive. An attacker with local user privileges could trigger the race condition without needing additional interaction, leading to a loss of availability. The flaw does not expose confidential data or alter system integrity, but it disrupts audio services and overall system responsiveness.

Affected Systems

MediaTek chipsets, including MT6880, MT6890, MT6990, MT6988, MT2735, and MT2737, are affected. The issue resides specifically in the Audio HAL of these devices.

Risk and Exploitability

Because the flaw requires user‑level execution on the device and no external network interaction, the risk is moderate. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be local, meaning an attacker must have access to the device or user involvement, which lowers the probability of widespread exploitation. The CVSS score is 5.5, indicating moderate severity.

Generated by OpenCVE AI on August 4, 2026 at 10:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek firmware patch ALPS10960026 for MT6880, MT6890, MT6990, and MT6988 or AUTO00851250 for MT2735 and MT2737.
  • After applying the patch, reboot the device to ensure the updated Audio HAL is in use.
  • If patching is delayed, reduce service exposure by disabling or restricting the audio subsystem until the patch can be installed.

Generated by OpenCVE AI on August 4, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt2737:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2735_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2737_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6880_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6990_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt2737
Mediatek mt2737 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware

Tue, 04 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Potential Local Denial of Service via Audio HAL Race Condition on MediaTek Chipsets

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.
Weaknesses CWE-367
References

Subscriptions

Mediatek Mt2735 Mt2735 Firmware Mt2737 Mt2737 Firmware Mt6880 Mt6880 Firmware Mt6890 Mt6890 Firmware Mt6988 Mt6988 Firmware Mt6990 Mt6990 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T19:46:26.124Z

Reserved: 2025-11-03T01:30:59.026Z

Link: CVE-2026-20492

cve-icon Vulnrichment

Updated: 2026-08-03T19:46:21.812Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:44.330

Modified: 2026-08-19T15:08:29.143

Link: CVE-2026-20492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:00:07Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition