CVE-2026-20532
Received Received - Intake

Double Free in APU Leading to Local DoS

Vulnerability report for CVE-2026-20532, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MediaTek, Inc.

Description

In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249024; Issue ID: MSV-9168.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mediatek apu *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-415 The product calls free() twice on the same memory address.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a double free issue in the apu component. A double free occurs when a program frees the same memory block twice, which can cause the application to crash. This leads to a local denial of service without requiring additional privileges or user interaction.

Impact Analysis

This vulnerability could cause your device to crash or become unresponsive due to the application handling the apu component failing. Since it requires no extra permissions or user action, it may affect system stability during normal use.

Compliance Impact

The provided CVE data does not specify any direct impact on compliance with standards like GDPR or HIPAA. The vulnerability involves a local denial of service due to a double free in the mediatek apu, which does not inherently relate to data protection or privacy requirements.

Mitigation Strategies

Apply the patch identified as ALPS11249024 to address the double free issue in the mediatek apu component. Ensure the update is deployed across all affected systems to prevent local denial of service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart