In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.
History

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt6813
Mediatek mt6813 Firmware
Mediatek mt6982vb
Mediatek mt6982vb Firmware
Mediatek mt6986
Mediatek mt6986 Firmware
Mediatek mt6986d
Mediatek mt6986d Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
CPEs cpe:2.3:h:mediatek:mt6813:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6982vb:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6986:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6986d:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6813_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6982vb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6986_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6986d_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt6813
Mediatek mt6813 Firmware
Mediatek mt6982vb
Mediatek mt6982vb Firmware
Mediatek mt6986
Mediatek mt6986 Firmware
Mediatek mt6986d
Mediatek mt6986d Firmware
Mediatek mt6988
Mediatek mt6988 Firmware

Wed, 05 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Out‑of‑Bounds Read in MediaTek CCCI Component

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Out‑of‑Bounds Read in MediaTek CCCI Component

Mon, 03 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published: 2026-08-03T02:05:55.740Z

Updated: 2026-08-03T18:55:15.763Z

Reserved: 2025-11-03T01:30:59.023Z

Link: CVE-2026-20490

cve-icon Vulnrichment

Updated: 2026-08-03T18:54:56.117Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:44.110

Modified: 2026-08-19T15:08:04.757

Link: CVE-2026-20490

cve-icon Redhat

No data.