In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899. | |
| Weaknesses | CWE-787 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2026-04-07T03:25:39.747Z
Reserved: 2025-11-03T01:30:59.013Z
Link: CVE-2026-20446
No data.
Status : Received
Published: 2026-04-07T04:17:13.797
Modified: 2026-04-07T04:17:13.797
Link: CVE-2026-20446
No data.
OpenCVE Enrichment
No data.