In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediatek
Mediatek mt6813 Mediatek mt6813 Firmware |
|
| CPEs | cpe:2.3:h:mediatek:mt6813:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt6813_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mediatek
Mediatek mt6813 Mediatek mt6813 Firmware |
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899. | |
| Weaknesses | CWE-787 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published: 2026-04-07T03:25:39.747Z
Updated: 2026-04-07T13:02:15.541Z
Reserved: 2025-11-03T01:30:59.013Z
Link: CVE-2026-20446
Updated: 2026-04-07T13:02:07.185Z
Status : Analyzed
Published: 2026-04-07T04:17:13.797
Modified: 2026-04-07T15:43:45.250
Link: CVE-2026-20446
No data.