CVE-2026-20469

Summary

In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533.

Affected Software

VendorProductVersion RangeStatus
MediaTek, Inc.MediaTek chipsetMT8186affected
MediaTek, Inc.MediaTek chipsetMT8188affected
MediaTek, Inc.MediaTek chipsetMT8195affected
MediaTek, Inc.MediaTek chipsetMT8365affected
MediaTek, Inc.MediaTek chipsetMT8370affected
MediaTek, Inc.MediaTek chipsetMT8371affected
MediaTek, Inc.MediaTek chipsetMT8390affected
MediaTek, Inc.MediaTek chipsetMT8391affected
MediaTek, Inc.MediaTek chipsetMT8395affected

Weaknesses

  • CWE-123: CWE-123 Write-what-where Condition

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References