CVE-2026-20415
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2026-02-02
Last updated on: 2026-02-03
Assigner: MediaTek, Inc.
Description
Description
In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363254; Issue ID: MSV-5617.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 15.0 | |
| mediatek | mt6897 | * |
| mediatek | mt6989 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-667 | The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors. |
| CWE-415 | The product calls free() twice on the same memory address. |