Race Condition in MDDP Allows Local Denial of Service
CVE-2026-20445

4.4MEDIUM

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
2 March 2026

What is CVE-2026-20445?

A race condition vulnerability in MDDP may result in a system crash, enabling a local denial of service scenario. This issue does not require user interaction for exploitation, allowing an attacker with system privileges to potentially disrupt services. It is essential to apply the provided patch ID ALPS10289875 to mitigate the risks associated with this security flaw.

Affected Version(s)

MediaTek chipset MT6835

MediaTek chipset MT6855

MediaTek chipset MT6878

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.