Description
In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A race condition in the handle_unmap_req function of the TIPC Virtio driver can corrupt memory, potentially allowing a local user to elevate privileges on the Android device. This vulnerability does not provide a path for remote code execution or require any special execution privileges beyond a local account. The flaw is a classic example of improper synchronization leading to memory corruption, as identified by CWE-362.

Affected Systems

Android devices that include the TIPC Virtio driver in tipc_virtio_dev.c are impacted. The bulletin does not specify a particular Android release, implying that any version containing the driver could be affected.

Risk and Exploitability

The CVSS score of 6.4 denotes moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because user interaction is not needed, the attack can be executed by any local user, making the risk significant for devices that run untrusted code or have compromised accounts.

Generated by OpenCVE AI on September 20, 2026 at 13:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check Google’s latest security bulletin for a patch that addresses the TIPC Virtio race condition and install the corresponding Android update.
  • If a patch is not yet available, consider disabling the TIPC Virtio driver or restricting its use through device policy until a fix is released.
  • Apply general Android hardening practices, such as enforcing app sandboxing, restricting local account privileges, and monitoring for anomalous kernel activity.

Generated by OpenCVE AI on September 20, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Race Condition in TIPC Virtio Driver Enables Local Privilege Escalation

Thu, 17 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Android Vulnerability in TIPC Virtio Device Enables Local Privilege Escalation

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Android Vulnerability in TIPC Virtio Device Enables Local Privilege Escalation

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:37.052Z

Reserved: 2026-06-23T16:10:45.837Z

Link: CVE-2026-56923

cve-icon Vulnrichment

Updated: 2026-09-15T20:08:35.316Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:28.060

Modified: 2026-09-21T17:18:15.987

Link: CVE-2026-56923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')