MediaTek MDDP race condition may crash system (local DoS)
CVE-2026-20445 Published on March 2, 2026
In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10289875; Issue ID: MSV-5184.
Vulnerability Analysis
CVE-2026-20445 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
What is a TOCTTOU Vulnerability?
The software checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the software to perform invalid actions when the resource is in an unexpected state. This weakness can be security-relevant when an attacker can influence the state of the resource between check and use. This can happen with shared resources such as files, memory, or even variables in multithreaded programs.
CVE-2026-20445 has been classified to as a TOCTTOU vulnerability or weakness.
Products Associated with CVE-2026-20445
Want to know whenever a new CVE is published for MediaTek products? stack.watch will email you.
Affected Versions
MediaTek, Inc. MediaTek chipset:- Version MT6835 is affected.
- Version MT6855 is affected.
- Version MT6878 is affected.
- Version MT6879 is affected.
- Version MT6883 is affected.
- Version MT6885 is affected.
- Version MT6886 is affected.
- Version MT6889 is affected.
- Version MT6893 is affected.
- Version MT6895 is affected.
- Version MT6897 is affected.
- Version MT6899 is affected.
- Version MT6983 is affected.
- Version MT6985 is affected.
- Version MT6989 is affected.
- Version MT6991 is affected.
- Version MT6993 is affected.
- Version MT8188 is affected.
- Version MT8678 is affected.
- Version MT8755 is affected.
- Version MT8771 is affected.
- Version MT8797 is affected.
- Version MT8798 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.