In Modem, there is a possible out of bounds read due to a missing permission check. This could...
zetlyn/cve-ghsa vulnerability ghsa GHSA-h6c4-mvxr-gf42 cve CVE-2026-20538 known 2026-10-05
https://github.com/advisories/GHSA-h6c4-mvxr-gf42
Properties
| cwe | CWE-126receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-20538",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-126",
"name": "Buffer Over-read"
}
],
"description": "In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.",
"ghsa_id": "GHSA-h6c4-mvxr-gf42",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-h6c4-mvxr-gf42",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-h6c4-mvxr-gf42"
},
{
"type": "CVE",
"value": "CVE-2026-20538"
}
],
"nvd_published_at": "2026-10-05T02:16:52Z",
"published_at": "2026-10-05T03:30:26Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-20538",
"https://www.mediatek.com/product-security-bulletin/October-2026",
"https://github.com/advisories/GHSA-h6c4-mvxr-gf42"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "In Modem, there is a possible out of bounds read due to a missing permission check. This could...",
"type": "unreviewed",
"updated_at": "2026-10-05T03:30:33Z",
"url": "https://api.github.com/advisories/GHSA-h6c4-mvxr-gf42",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| severity | unknownreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-20538",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-126",
"name": "Buffer Over-read"
}
],
"description": "In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.",
"ghsa_id": "GHSA-h6c4-mvxr-gf42",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-h6c4-mvxr-gf42",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-h6c4-mvxr-gf42"
},
{
"type": "CVE",
"value": "CVE-2026-20538"
}
],
"nvd_published_at": "2026-10-05T02:16:52Z",
"published_at": "2026-10-05T03:30:26Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-20538",
"https://www.mediatek.com/product-security-bulletin/October-2026",
"https://github.com/advisories/GHSA-h6c4-mvxr-gf42"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "In Modem, there is a possible out of bounds read due to a missing permission check. This could...",
"type": "unreviewed",
"updated_at": "2026-10-05T03:30:33Z",
"url": "https://api.github.com/advisories/GHSA-h6c4-mvxr-gf42",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
In Modem, there is a possible out of bounds read due to a missing permission check. This could...
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.