CVE-2026-20542: Use After Free
Published Oct 5, 2026
·Updated
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143.
Affected Software
1 affected component
MediaTek apusys
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apusysto a version that resolves this vulnerability.Patch ALPS11076799
Event History
Oct 5, 2026
CVE Published
via MITRE·01:40 AM
Data Sourced
via MITRE·01:40 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access must an attacker already have?
The attacker must already have obtained the System privilege. The issue is described as enabling local escalation of privilege from that position.
2
Is user interaction required for exploitation?
No. The advisory states that user interaction is not needed.
3
Which identifiers can be used to track the vendor fix?
The patch is identified as ALPS11076799, and the associated issue ID is MSV-8143.