Home

Description

In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.

PUBLISHED Reserved 2025-11-03 | Published 2026-04-07 | Updated 2026-04-07 | Assigner MediaTek

Problem types

CWE-787 Out-of-bounds Write

Product status

Default status
unaffected

MT6813
affected

References

corp.mediatek.com/product-security-bulletin/April-2026

cve.org (CVE-2026-20446)

nvd.nist.gov (CVE-2026-20446)

Download JSON