CVE-2026-20438: Race Condition
Published Mar 2, 2026
·Updated
In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431920; Issue ID: MSV-5835.
Affected Software
12 affected components
All of the following
Google Android=15.0
Any of the following
MediaTek Mt2718
MediaTek Mt6899
MediaTek Mt6991
MediaTek Mt8168
MediaTek Mt8169
MediaTek Mt8186
MediaTek Mt8188
MediaTek Mt8678
MediaTek Mt8695
MediaTek Mt8696
MediaTek Mt8793
Event History
Mar 2, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-20438?
CVE-2026-20438 has a critical severity rating due to the potential for local escalation of privilege.
2
How do I fix CVE-2026-20438?
To fix CVE-2026-20438, apply the patch ID ALPS10431920 provided by the vendor.
3
What causes the vulnerability identified by CVE-2026-20438?
CVE-2026-20438 is caused by a race condition that leads to a possible out of bounds write.
4
Is user interaction required to exploit CVE-2026-20438?
No, user interaction is not needed for the exploitation of CVE-2026-20438.
5
What impact does CVE-2026-20438 have on affected systems?
CVE-2026-20438 could lead to local escalation of privilege by a malicious actor who has obtained System privilege.