CVE-2026-20446: Integer Overflow
In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20446?
CVE-2026-20446 is considered a medium severity vulnerability that can lead to local denial of service.
How do I fix CVE-2026-20446?
To fix CVE-2026-20446, apply the patch identified by Patch ID ALPS09963054.
What causes CVE-2026-20446?
CVE-2026-20446 is caused by an integer overflow leading to a possible out of bounds write in the secure boot process.
Who is affected by CVE-2026-20446?
CVE-2026-20446 affects devices that utilize MediaTek Mt6813 firmware.
Can CVE-2026-20446 be exploited remotely?
CVE-2026-20446 cannot be exploited remotely as it requires local access and user execution privileges.