Impact
The vulnerability resides in the smmu_detach_dev_nested function in arm‑smmu‑v3.c. It allows a local user to bypass improper input validation and gain System execution privileges, which constitutes an elevation of privilege. The weakness is an improper input validation flaw (CWE‑20).
Affected Systems
The affected product is Google Android. The vulnerability exists in the smmu_detach_dev_nested path of the Android kernel, and all Android devices that include this code are potentially affected. No specific Android versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local; no user interaction is required, and the attacker could exploit the flaw to elevate privileges to system level.
OpenCVE Enrichment