CVE-2026-20524: Input Validation
Published Oct 5, 2026
·Updated
In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170.
Affected Software
1 affected component
MediaTek APU
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aputo a version that resolves this vulnerability.Patch ALPS11249004
Event History
Oct 5, 2026
CVE Published
via MITRE·01:39 AM
Data Sourced
via MITRE·01:39 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation is local and can lead to escalation of privilege. No additional execution privileges are needed, and user interaction is not required.
2
How can I identify the vendor fix for this issue?
The vendor identifies the fix as Patch ID ALPS11249004 and tracks the issue as MSV-9170.