Description
In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the smmu_detach_dev_nested function in arm‑smmu‑v3.c. It allows a local user to bypass improper input validation and gain System execution privileges, which constitutes an elevation of privilege. The weakness is an improper input validation flaw (CWE‑20).

Affected Systems

The affected product is Google Android. The vulnerability exists in the smmu_detach_dev_nested path of the Android kernel, and all Android devices that include this code are potentially affected. No specific Android versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 6.7 indicates a medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local; no user interaction is required, and the attacker could exploit the flaw to elevate privileges to system level.

Generated by OpenCVE AI on September 17, 2026 at 08:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch that addresses smmu_detach_dev_nested
  • If a patch is not yet available, configure the device to block or disable the SMMU driver for non‑essential operations
  • Enable audit logging for SMMU detach events and review logs for anomalous privilege escalation activity

Generated by OpenCVE AI on September 17, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Input Validation in smmu_detach_dev_nested

Wed, 16 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Input Validation in smmu_detach_dev_nested

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Weaknesses CWE-20
Vendors & Products Google
Google android
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:25.271Z

Reserved: 2026-07-02T05:39:38.720Z

Link: CVE-2026-58718

cve-icon Vulnrichment

Updated: 2026-09-15T20:02:44.297Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:32.650

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-58718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:30:15Z

Weaknesses
  • CWE-20

    Improper Input Validation