CVE-2026-20411: Use After Free
Published Feb 2, 2026
·Updated
In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5737.
Affected Software
28 affected components
All of the following
Any of the following
Google Android=13.0
Google Android=14.0
Google Android=15.0
Google Android=16.0
Any of the following
MediaTek Mt6878
MediaTek Mt6879
MediaTek Mt6881
MediaTek Mt6886
MediaTek Mt6895
MediaTek Mt6897
MediaTek Mt6899
MediaTek Mt6983
MediaTek Mt6985
MediaTek Mt6989
MediaTek Mt6991
MediaTek Mt6993
MediaTek Mt8168
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8365
MediaTek Mt8370
MediaTek Mt8390
MediaTek Mt8395
MediaTek Mt8666
MediaTek Mt8667
MediaTek Mt8673
MediaTek Mt8676
MediaTek Mt8793
Event History
Feb 2, 2026
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-20411?
The severity of CVE-2026-20411 is high due to potential privilege escalation leading to local denial of service.
2
How do I fix CVE-2026-20411?
To fix CVE-2026-20411, install the patch provided under Patch ID ALPS10351676.
3
What systems are affected by CVE-2026-20411?
CVE-2026-20411 affects Google Android versions 13.0, 14.0, 15.0, and 16.0.
4
Is user interaction required to exploit CVE-2026-20411?
No, user interaction is not needed to exploit CVE-2026-20411 once the attacker has System privileges.
5
What type of vulnerability is CVE-2026-20411?
CVE-2026-20411 is a use after free vulnerability that can lead to privilege escalation.