CVE-2026-20527: Out-of-bounds Read
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY01864925 / MOLY01210562
Event History
Frequently Asked Questions
What conditions are required for exploitation?
A UE must connect to a rogue base station controlled by the attacker. No additional execution privileges or user interaction are required.
What is the practical impact if exploitation succeeds?
The issue can cause a system crash in the modem, resulting in remote denial of service.
How can I identify the vendor fix for this issue?
MediaTek identifies the fixes with Patch IDs MOLY01864925 and MOLY01210562. The associated issue ID is MSV-8303.