PatchSiren

MediaTek, Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20456

A missing bounds check in the MediaTek WLAN STA driver can cause a system crash, leading to local denial of service. The vulnerability requires User execution privileges but does not require user interaction for exploitation. The issue has been assigned CWE-787 (Out-of-bounds Write) and is addressed by Patch ID WCNCR00480851.

Review MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20455

A missing bounds check in the geniezone component creates an out-of-bounds write condition. The vulnerability requires an attacker to already hold System privilege, limiting exposure to post-compromise scenarios. No user interaction is needed for exploitation. The issue has been addressed via patch ALPS10873936 (Issue ID: MSV-6784).

Review MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20454

A race condition in the geniezone component creates a possible out-of-bounds write. Successful exploitation could allow a malicious actor with existing System privileges to escalate privileges further. No user interaction is required for exploitation. The vulnerability has been addressed with Patch ID ALPS10873936 (Issue ID: MSV-6786).

Review MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20453

A missing bounds check in the geniezone component creates an out-of-bounds write condition that could enable local privilege escalation. The vulnerability requires the attacker to already hold System privileges, meaning it represents a privilege-escalation path rather than an initial compromise vector. No user interaction is needed for exploitation. The issue has been addressed with patch ID ALPS10886526.

Review MediaTek, Inc. CVE published 2026-06-01

CVE-2026-20452

A heap buffer overflow vulnerability in a WLAN Access Point (AP) driver may allow remote proximal/adjacent attackers to achieve code execution. The flaw requires User execution privileges but does not require user interaction for exploitation. The vulnerability was disclosed in MediaTek's June 2026 Product Security Bulletin with Patch ID WCNCR00480138 and Issue ID MSV-6295. The weakness is classified as C [truncated]