Home

Description

In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431920; Issue ID: MSV-5835.

PUBLISHED Reserved 2025-11-03 | Published 2026-03-02 | Updated 2026-03-30 | Assigner MediaTek

Problem types

CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

Product status

Default status
unaffected

MT2718
affected

MT6899
affected

MT6991
affected

MT8168
affected

MT8169
affected

MT8186
affected

MT8188
affected

MT8678
affected

MT8695
affected

MT8696
affected

MT8793
affected

References

corp.mediatek.com/product-security-bulletin/March-2026

cve.org (CVE-2026-20438)

nvd.nist.gov (CVE-2026-20438)

Download JSON