CVE-2026-20579: MediaTek vdec vulnerability
Published Oct 5, 2026
·Updated
In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9800.
Affected Software
1 affected component
MediaTek vdec
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11383899
Event History
Oct 5, 2026
CVE Published
via MITRE·01:39 AM
Data Sourced
via MITRE·01:39 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need before exploiting this issue?
The attacker must already have System privilege. Exploitation can then lead to local escalation of privilege without user interaction.
2
What identifier should I use to track the vendor fix?
The listed patch ID is ALPS11383899, and the vendor issue ID is MSV-9800.