CVE-2026-20491: Medium severity med vulnerability
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS10981478 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch AUTO00851173 - Compensating control
Mitigate local DoS risk by restricting access/permissions of the affected component that is reachable with user execution privileges, since the issue requires user execution privileges but no user interaction for exploitation (Issue ID: MSV-7652).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20491?
CVE-2026-20491 has a risk rating of 21, indicating significant potential impact.
How do I fix CVE-2026-20491?
To fix CVE-2026-20491, apply the patches identified as ALPS10981478 for compatible devices.
What can be exploited with CVE-2026-20491?
CVE-2026-20491 can be exploited to achieve local denial of service due to an out of bounds write.
Who needs permissions to exploit CVE-2026-20491?
Exploitation of CVE-2026-20491 requires user execution privileges.
Is user interaction needed to exploit CVE-2026-20491?
No, user interaction is not needed for the exploitation of CVE-2026-20491.