CVE-2026-20531: Use After Free
Published Oct 5, 2026
·Updated
In apu, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249016; Issue ID: MSV-9169.
Affected Software
1 affected component
MediaTek APU
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aputo a version that resolves this vulnerability.Patch ALPS11249016
Event History
Oct 5, 2026
CVE Published
via MITRE·01:40 AM
Data Sourced
via MITRE·01:40 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs local access. No additional execution privileges are required, and exploitation does not require user interaction.
2
What could successful exploitation allow?
Successful exploitation could cause memory corruption and lead to local escalation of privilege.
3
How can I identify the vendor fix for this issue?
The listed patch identifier is ALPS11249016, and the vendor issue identifier is MSV-9169.