Type Confusion in MediaTek products - CVE-2026-20451

 

Type Confusion in MediaTek products - CVE-2026-20451

Published: May 4, 2026


Vulnerability identifier: #VU129563
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-20451
CWE-ID: CWE-843
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
MT2718
MT6899
MT6985
MT6989
MT6991
MT8115
MT8186
MT8188
MT8196
MT8365
MT8367
MT8370
MT8371
MT8390
MT8391
MT8395
MT8676
MT8678
MT8766
MT8768
MT8775
MT8781
MT8786
MT8788E
MT8791T
MT8792
MT8793
MT8796
MT8873
MT8883
MT8893
MT8910
Software vendor:
MediaTek

Description

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to type confusion in slbc when processing crafted local input. A local user can trigger an out-of-bounds write to cause a denial of service.


Remediation

Install security update from vendor's website.

External links