Description
In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.
Published: 2026-09-07
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free in the MediaTek GPU driver that can cause a system crash and may disclose local information. It requires user execution privileges and user interaction to be triggered.

Affected Systems

MediaTek Inc. chipset GPU components. No specific firmware or kernel versions are listed in the advisory.

Risk and Exploitability

EPSS is not available and the vulnerability is not listed in CISA KEV. The CVSS score is 5.5. It is not publicly exploited at present. Exploitation requires local user privilege and user interaction, and the impact is limited to the local system without offering remote code execution.

Generated by OpenCVE AI on September 7, 2026 at 14:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch ALPS11122991 to the MediaTek GPU firmware.
  • Reboot the device to ensure the patch is fully integrated.
  • Limit GPU usage to trusted applications or disable GPU acceleration if feasible.

Generated by OpenCVE AI on September 7, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in MediaTek GPU May Crash System and Leak Sensitive Data

Mon, 07 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 07 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in MediaTek GPU May Crash System and Leak Sensitive Data

Mon, 07 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.
Weaknesses CWE-416
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-09-07T10:24:27.621Z

Reserved: 2025-11-03T01:30:59.031Z

Link: CVE-2026-20515

cve-icon Vulnrichment

Updated: 2026-09-07T10:24:19.637Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T02:17:20.257

Modified: 2026-09-08T18:38:19.590

Link: CVE-2026-20515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:30:17Z

Weaknesses