CVE-2026-20492
Received Received - Intake

Audio HAL Race Condition Leads to Local DoS

Vulnerability report for CVE-2026-20492, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: MediaTek, Inc.

Description

In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mediatek audio_hal From ALPS10960026 (inc) to AUTO00851250 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a race condition vulnerability in the Audio HAL (Hardware Abstraction Layer) that could cause the system to become unresponsive. It requires user execution privileges but does not need user interaction to be exploited, leading to a local denial of service.

Detection Guidance

This vulnerability involves a race condition in Audio HAL that could cause system unresponsiveness. Detection requires checking for system hangs or unresponsive audio services during concurrent operations. Monitor system logs for audio-related errors or crashes. No specific commands are provided in the context.

Impact Analysis

An attacker with local access could exploit this to freeze or crash the system, disrupting normal operations. This may cause loss of functionality until the device is rebooted or the issue is patched.

Compliance Impact

This vulnerability could lead to a local denial of service due to a race condition in Audio HAL, requiring user execution privileges. It may impact compliance with standards like GDPR or HIPAA by potentially disrupting system availability or integrity, which are critical for maintaining secure and reliable environments.

Mitigation Strategies

Apply the provided patches: ALPS10960026 for MT6880, MT6890, MT6990, MT6988 or AUTO00851250 for MT2735, MT2737. Ensure the Audio HAL is updated to the latest version to address the race condition.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20492. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart