CVE-2026-20477: Medium severity MediaTek Mt8910 Firmware vulnerability
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11009963
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20477?
CVE-2026-20477 has a medium severity rating of 6 according to the CVSS 3.1 metrics.
How do I fix CVE-2026-20477?
To fix CVE-2026-20477, apply the patch identified by Patch ID ALPS11009963.
What are the potential impacts of CVE-2026-20477?
CVE-2026-20477 could lead to local escalation of privilege for a malicious actor with System privilege.
Is user interaction required to exploit CVE-2026-20477?
No, user interaction is not needed for the exploitation of CVE-2026-20477.
What type of vulnerability is CVE-2026-20477?
CVE-2026-20477 is characterized as an out of bounds write vulnerability due to a missing bounds check.