What the vulnerability does

01Description

In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.

Key dates

02Disclosure timeline

April 7, 2026 CVE published
April 7, 2026 Record updated